Privacy Policy

The minimum data, handled with care.

Vertirite is built for buyers in regulated industries. We collect the minimum data needed to operate the control plane, and we never sell, rent, or share customer data with third parties for marketing purposes.

Effective 2026-05-01

This is not legal advice. We are not your attorney. This page describes how Vertirite handles customer data; for the contractual privacy terms that govern your deployment, see your Master Services Agreement and Data Processing Addendum.
§1

Information we collect

To operate the Vertirite control plane we collect:

  • Account information — name, email, organisation, role, billing contact. Provided by you when an order form or self-serve sign-up is completed.
  • Broker telemetry — connection counts, request latency, mode-authority transitions, capability-registry version in force. Used to operate, not to analyse the contents of your actions.
  • Audit log content — every action your protected systems route through Vertirite, with cryptographic attribution. On the self-host tier this never leaves your infrastructure. On hosted tiers it lives in the Vertirite-managed audit store you see in the operator console.
  • Anonymous product analytics — page views and feature-use counts on the marketing site and operator console. No content of customer actions, no audit-row contents, no payloads. Aggregated only.

We do not collect biometric data, location data, or third-party social-graph data. We do not run advertising trackers on vertirite.com.

§2

How we use it

  • Operate the service — route approval requests, verify signatures, append to the audit log, render the operator console.
  • Surface anomalies — detect mode-authority regressions, capability-registry drift, and approval-queue backlog so we can notify you before they become incidents.
  • Bill you — pass billing identifiers and tier information to Stripe (see §4 sub-processors).
  • Support you — respond to email, investigate incidents, write postmortems. Support staff access is logged.

We do not sell, rent, or share customer data with third parties for marketing purposes. We do not train AI models on your data.

§3

Where customer data lives

Where data sits depends on the tier you purchased. The control plane is designed so that the path is auditable in every case.

  • Open Source / self-host (when shipped) — broker, audit log, and capability registry run entirely on customer-controlled infrastructure. Vertirite operates no data plane. You hold every key.
  • Team and Business (hosted) — broker and audit store run on Vertirite-managed infrastructure. Encryption at rest uses our keys today; customer-supplied KMS keys are an Enterprise-tier option. Same-host service traffic stays on loopback or the Docker bridge; cross-host traffic stays on the Tailscale overlay you control. See Networking Rules in our public docs for the audit trail behind that claim.
  • Enterprise — self-host is the default. For customers who select the Vertirite-hosted Enterprise option, tenants are geographically isolated to the region you specify in the order form (US-East, US-West, EU-West today; APAC on request). Customer-supplied KMS keys (AWS KMS, Azure Key Vault, GCP CMEK) are supported.
§4

Sub-processors

A short list, current as of 2026-05-01. Vertirite will give customers thirty days’ notice via email before adding a new sub-processor that handles customer data.

  • Stripe — billing and invoicing for Team and Business tiers. Receives customer name, billing email, billing address, and tier identifiers. Does not receive audit-log content or any customer action data.
  • Drata — compliance evidence collection for our in-flight SOC 2 Type 2 audit. Reads metadata from our internal systems; does not touch tenant audit logs.
  • AWS — hosted-tier data plane (broker, audit store, operator console) for Team, Business, and the Vertirite-hosted Enterprise option. Encryption at rest and in transit applies in every region.
  • Apple Push Notification Service and Firebase Cloud Messaging — when the Vertirite Notify companion app ships, Apple and Google are used only as wake-up channels. The approval payload itself travels on a WebSocket the device opens back to Vertirite-managed relay infrastructure; Apple and Google never see the contents of an approval. See the architecture spec referenced in our public docs for the full push-channel diagram.
§5

Data retention

  • Audit log content — retention follows the tier you purchased. Team: 30 days. Business: full retention for the duration of the contract. Enterprise: per the retention schedule negotiated in the order form. See the pricing page for the per-tier defaults.
  • Account data — retained for the active life of the account. Deleted within thirty days of cancellation, except where a longer retention is required by tax, accounting, or applicable law.
  • Anonymous product analytics — aggregated; individual records expire within ninety days.
  • Backups — encrypted backups of hosted-tier audit stores are retained per the tier’s retention window and pruned on the same cadence.
§6

Your rights

Under GDPR (if you are in the European Economic Area or the United Kingdom) and CCPA (if you are a California resident), you have the following rights — Vertirite extends them to all customers regardless of jurisdiction.

  • Access — request a copy of the data we hold about you.
  • Correction — ask us to correct inaccurate data.
  • Deletion — invoke the cascading delete. The operator console exposes a self-serve delete; the equivalent API call is DELETE /v1/me. Cascading delete clears your account, your tenant data, and revokes downstream credentials (e.g. model-router team membership).
  • Portability — request an export of your audit log in JSON Lines or signed PDF (Business and Enterprise tiers).
  • Objection — object to processing for any purpose beyond operating the service (we do not currently process for any other purpose, but the right stands).

Requests are honoured within thirty days. Email [email protected] to start a request.

§7

Changes to this policy

When this policy changes, Vertirite will notify the registered billing contact for each active account by email and post a version diff alongside the new effective date at the top of this page. Material changes carry thirty days’ notice before taking effect.

§8

Contact

Privacy questions, data-subject requests, sub-processor concerns: [email protected].

For security-incident disclosures specifically, see our security page and email [email protected].

A formal DMCA takedown mechanism is not yet in place; takedown requests should be directed to [email protected] and will be handled on a best-effort basis pending the formal process.

Need our DPA, BAA, or sub-processor list?

Email [email protected]. We respond within one business day during US business hours.

Email [email protected]