Security & Trust
Make the data boundary explicit before you connect a source.
Storage, processing, model access, sources, destinations, and exports can cross different systems. This page explains what to confirm so security and privacy requirements match the actual deployment.
Architecture
Start with where each type of data lives.
Vendo-managed storage and supported customer-managed warehouse workflows have different boundaries. Document the chosen path before approving access.
Storage choices
Use Vendo-managed storage or scope a supported customer-managed BigQuery workflow. Processing boundaries, regions, network paths, and service accounts must be confirmed for the chosen setup.
AI provider scope
Confirm which model provider, credentials, tools, prompts, retention settings, and data fields apply before enabling an Agent workflow.
Export and exit planning
Document where source data, prepared tables, models, files, and configuration live, and agree the export or handover process for each asset.
Compliance & Privacy
Turn privacy requirements into configuration and contracts.
Do not rely on a blanket compliance statement. Confirm roles, purposes, regions, retention, deletion, subprocessors, and incident obligations for the intended workflow.
Privacy responsibilities
Your team remains responsible for lawful collection, consent, purpose, retention, access, deletion, and destination use. Confirm Vendo’s processor role and contractual terms for your deployment.
Encryption requirements
Confirm encryption in transit and at rest for Vendo, your warehouse, each source, each destination, backups, and any exported files during security review.
Data residency
Residency depends on the selected storage, processing, model, source, destination, and support paths. Treat region requirements as a scoped contractual item.
Data minimisation
Select only the fields needed for the documented purpose and define retention, access, deletion, and downstream-delivery rules during setup.
Access Controls
Use the controls that exist—and identify the controls you still need.
Current roles, activity records, and any enterprise identity requirements should be reviewed against your access policy.
Owner and member roles
Current workspace access uses Owner and Member roles. Do not assume field-level or action-level permissions unless they are explicitly confirmed for your account.
Activity records
Use the available activity and job records to inspect supported actions and runs. They are not presented as a complete immutable audit archive.
SSO (Enterprise)
If single sign-on or identity-provider controls are required, confirm protocol, enforcement, provisioning, recovery, and availability as part of enterprise scope.
Monitoring & Quality
Inspect job health without overstating coverage.
Monitoring can show supported job and product activity. It cannot guarantee complete data or record every change in an external system.
Server-side tracking
Reduce dependence on browser execution by sending events observed by your server or another approved source. This cannot reconstruct unobserved events or bypass consent.
Pipeline monitoring
Review the status, last successful run, record counts, warnings, and errors available for each configured job. Alert behavior depends on the workflow.
Timeline and Memory
Timeline records supported product activity. Memory stores short facts for later Agent conversations. Neither is a substitute for a complete security audit log.