Skip to main content
Vendo

Security & Trust

Make the data boundary explicit before you connect a source.

Storage, processing, model access, sources, destinations, and exports can cross different systems. This page explains what to confirm so security and privacy requirements match the actual deployment.

Architecture

Start with where each type of data lives.

Vendo-managed storage and supported customer-managed warehouse workflows have different boundaries. Document the chosen path before approving access.

Storage choices

Use Vendo-managed storage or scope a supported customer-managed BigQuery workflow. Processing boundaries, regions, network paths, and service accounts must be confirmed for the chosen setup.

AI provider scope

Confirm which model provider, credentials, tools, prompts, retention settings, and data fields apply before enabling an Agent workflow.

Export and exit planning

Document where source data, prepared tables, models, files, and configuration live, and agree the export or handover process for each asset.

Compliance & Privacy

Turn privacy requirements into configuration and contracts.

Do not rely on a blanket compliance statement. Confirm roles, purposes, regions, retention, deletion, subprocessors, and incident obligations for the intended workflow.

Privacy responsibilities

Your team remains responsible for lawful collection, consent, purpose, retention, access, deletion, and destination use. Confirm Vendo’s processor role and contractual terms for your deployment.

Encryption requirements

Confirm encryption in transit and at rest for Vendo, your warehouse, each source, each destination, backups, and any exported files during security review.

Data residency

Residency depends on the selected storage, processing, model, source, destination, and support paths. Treat region requirements as a scoped contractual item.

Data minimisation

Select only the fields needed for the documented purpose and define retention, access, deletion, and downstream-delivery rules during setup.

Access Controls

Use the controls that exist—and identify the controls you still need.

Current roles, activity records, and any enterprise identity requirements should be reviewed against your access policy.

Owner and member roles

Current workspace access uses Owner and Member roles. Do not assume field-level or action-level permissions unless they are explicitly confirmed for your account.

Activity records

Use the available activity and job records to inspect supported actions and runs. They are not presented as a complete immutable audit archive.

SSO (Enterprise)

If single sign-on or identity-provider controls are required, confirm protocol, enforcement, provisioning, recovery, and availability as part of enterprise scope.

Monitoring & Quality

Inspect job health without overstating coverage.

Monitoring can show supported job and product activity. It cannot guarantee complete data or record every change in an external system.

Server-side tracking

Reduce dependence on browser execution by sending events observed by your server or another approved source. This cannot reconstruct unobserved events or bypass consent.

Pipeline monitoring

Review the status, last successful run, record counts, warnings, and errors available for each configured job. Alert behavior depends on the workflow.

Timeline and Memory

Timeline records supported product activity. Memory stores short facts for later Agent conversations. Neither is a substitute for a complete security audit log.