Security
Built inside your walls.Gated at every write.
An agent that touches your customers and your money deserves more scrutiny than any other software you buy. Here that scrutiny starts with architecture: there is no Vulc cloud to trust, because there is no Vulc cloud. The system runs in your environment, behind gates you set. This page is the discipline every build ships with.
- Your environment
- Least privilege
- Approval gates
- Audit trail
- Loud failure
- Clean handoff
The discipline
Architecture first.Promises second.
Your environment
The system runs on your accounts and your infrastructure. Your data stays where it already lives, under contracts you already signed. If Vulc disappeared tomorrow, everything would keep running.
Least privilege
Each agent gets scoped credentials per integration, sized to its job and nothing more. The support agent can draft a refund. The research agent cannot write anywhere at all.
Approval gates
Every write action stops for your sign-off. You decide which routine actions earn standing approval, where the money thresholds sit, and what stays off-limits entirely.
Audit trail
Every draft, decision and send is logged: which agent acted, on what, with what context, and who approved it. When you want to know why something happened, the answer is on record.
Loud failure
Failure states are designed before launch, not discovered after. When something breaks, the alert names the failing step and the system holds instead of guessing. Nothing fails silently.
Clean handoff
At handoff the credentials rotate to you, documented in the runbooks. Our access is granted by you and revocable by you, and after handoff nothing standing remains.
The quench, expanded
Nothing meets productionbefore the quench.
Stage three of every build is hardening: permissions, gates, failure states and volume, tested before the system touches a real customer. The quench ends the only way it can: with your sign-off on the go-live.
Quench report · illustrative
- permissions · scoped per integration · pass
- gates · every write action covered · pass
- failure drill · alert fired, named the step · pass
- volume test · run against real load · pass
Production go-live
quench passed, checklist documented
Needs your call
approval-first. nothing ships without you.
Who holds what
A short list,by design.
Most vendors need a long page to explain where your data goes. Ours is three rows, because the architecture keeps it that way.
Your accounts and infrastructure
Everything: data, code, credentials. Under your contracts, your keys, your jurisdiction.
The model provider
Prompt context per request, under commercial API terms. Which provider, and what reaches it, is decided with you and documented in the build.
Vulc
Your contact details and the build documentation. During the build, scoped access you grant and can revoke. After handoff, nothing standing.
Certifications, honestly
We wear no badges.You inherit yours.
Vulc holds no security certifications and rents you no infrastructure, so there is nothing of ours to audit. Your deployment inherits the posture of the stack it runs on: your cloud, your store, your email platform, and the certifications they already carry. Vulc operates from the Netherlands under the GDPR. Every build is documented at handoff: a permissions map per agent, the data flows, and the runbooks for incidents and revocation. If a vendor shows you a badge wall for a system that runs in your own account, ask what the badges are for.
Security questions: security@vulc.ai
The pack
Ask for the documents.You get them.
Six documents back this page. The overview is ready to read today. The rest are filled in for your build and signed before anything touches production. Ask and they arrive, no call required first.
Security overview
This page in document form, with the subprocessor list and the common questions answered.
Architecture overview
Per build: deployment model, environments, access, secrets, logging, change management.
Agent permissions map
Per build: what each agent may read, draft and write, with the gate and threshold on every row.
Data flow map
Per build: what data moves where, what leaves your systems, and what is deliberately not sent.
Incident response runbook
Per build: how to stop an agent, contain, assess, roll back and report. Yours at handoff.
Data processing agreement
Signed before we touch a system of yours that holds personal data.
or write to security@vulc.ai