Security & Trust Centre
ISO 27001 certified

AI that acts on your store, with guardrails built in.

Vortex IQ can act on commerce workflows, so trust is part of the product. Writes follow least-privilege access and human approval by default. Audit trails, staging and rollback apply where the connected platform and workflow support them.

The foundations

Security is a default, not an add-on.

Four principles hold up everything we build. They apply to your data at rest, your data in motion, and every action an agent takes on your behalf.

Certified ISO 27001

Our information security management system is independently certified to ISO/IEC 27001: the global standard for managing risk across people, process, and technology.

Independently audited

Encrypted, in transit & at rest

Data is encrypted in transit with TLS and at rest in our cloud infrastructure. Secrets and credentials are stored in managed key vaults, never in plain text.

TLS + at-rest encryption

Least-privilege access

Agents and people get the narrowest scopes that get the job done, nothing more. Access is role-based, time-bound and revocable, and we only request the store permissions we need.

Scoped & revocable

UK & EU GDPR aligned

We process personal data in line with UK GDPR and the EU GDPR, with a clear lawful basis, data-subject rights honoured, and a Data Processing Agreement available on request.

UK GDPR + EU GDPR
How agents act safely

Keep production writes inside your controls.

An agent can detect a problem and draft work. Human approval is the default for production writes, while bounded automation is enabled only for an explicitly agreed workflow.

1
Human approval by default

The agent proposes scoped work in plain English. A person reviews production writes unless bounded automation has been explicitly enabled for that workflow.

2
Full audit trail

Who proposed it, who approved it, what changed and when: every Action is logged immutably, so you always have a defensible record of what happened.

3
Rollback where supported

Supported workflows preserve a recovery path before the write. The rollback method depends on the platform and change type.

4
Staging & backups

Vortex Apps provides staging and restore points for supported commerce-platform workflows, so your team can review the available recovery path before deployment.

Action · awaiting approvalScoped
Detected: 142 products missing meta titlesNerve Centre · catalogue
Proposed: generate & apply SEO titlespreview before publish
Restore point savedrollback ready · Vortex Apps
Approve changeRollback
Independently tested

Tested by an independent security firm, not just our own team.

Vortex IQ undergoes independent penetration testing by SecureLayer7 Technologies, using a Grey Box methodology aligned with OWASP Top 10, OWASP ASVS 4.0.2, NIST SP 800-115 and PTES. The most recent assessment ran from 2 to 4 June 2025 and identified seven findings, one critical, one high and five low. Every finding was remediated and confirmed closed during the retest.

Role-Based Access Control (RBAC)Available. Access is scoped by role and revocable.
Multi-factor authentication (MFA)Available.
Single sign-onAvailable with Google. SAML and OIDC federation for other identity providers is in progress.
SCIM user provisioningPlanned.
Audit logsAvailable. Every Action is logged immutably: who proposed it, who approved it, and what changed.
Session managementAvailable.
Pseudonymisation in reportingIn progress for Vortex Mind. Some teams need to see who did what in order to act on a report, and others must not. Reporting will let a user choose named individuals or pseudonymous identifiers, and an organisation will be able to enforce pseudonymisation for everyone, so the choice is set once by whoever owns the policy.
Compliance & certifications

The paperwork your security team will ask for.

ISO/IEC 27001Independently certified information security management system covering how we manage data, access and operational risk. Certificate available on request.
SOC 2SOC 2 Type II audit in progress. We will publish the completed report here rather than claim it early.
UK GDPR & EU GDPRWe process personal data lawfully, honour data-subject rights, and minimise what we collect. Our practices align with the UK GDPR and the EU GDPR.
Data Processing Agreement (DPA)A DPA covering controller/processor responsibilities and international transfers is available on request. Just talk to us.
Sub-processorsWe use a small set of vetted cloud and AI sub-processors to run the platform. A current list is available on request so you can complete your own due diligence.
BigCommerce Elite PartnerRecognised in BigCommerce's AI-Pilots Elite tier, its highest technology-partner tier, following the Microsoft GenAI Accelerator.
Adobe Commerce Rockstar, Winner (2023)DryRun Pro, built by the Vortex IQ team, won the Developer Tooling category at Adobe Commerce Rockstar, chosen from over 65 submissions and showcased on stage at Adobe Summit. Independently judged by Adobe's own engineering and product leadership.

We only claim what we hold today: ISO 27001 certification, GDPR alignment, and BigCommerce Elite Partner status. SOC 2 is genuinely in progress, not yet complete, and we say so rather than implying otherwise. We will not overstate our posture; if a framework is on the roadmap rather than in place, we will say so.

Policies & documentation

Read our security & data-protection policies.

The policies and documents that govern how we build, run and secure the platform. Each is maintained and dated, and available here in full.

Public Claims MethodologyHow Vortex IQ defines, calculates, qualifies and reviews the operational figures used on this website.Information Security PolicyHow we protect the confidentiality, integrity and availability of information across people, process and technology.Data Protection Addendum (DPA)Controller/processor responsibilities, security measures and international-transfer safeguards for personal data.Sub-processorsThe vetted cloud and AI sub-processors we use to run the platform, with regions and retention terms.Incident Response and Breach Notification PolicyHow we detect, contain, investigate and notify on security incidents and personal-data breaches.Secure SDLC and Change Management PolicySecure development, code review, testing and controlled, reversible change management.AI and Model Governance PolicyHow we select, govern and monitor AI models, and keep customer data out of model training.Vendor and Third-party Risk PolicyHow we assess, tier and monitor third-party vendors and sub-processors for security and compliance.Corporate Security PlanOrganisational, physical and personnel security controls that protect the business and its assets.Mobile Device Management (MDM) PolicyControls for company and BYOD devices that access Vortex IQ systems and data.Business Continuity PlanHow we keep critical services running and recover operations during a disruption.Disaster Recovery PlanMulti-cloud, multi-region recovery objectives and procedures for restoring service after an outage.
Reliability & status

See how the platform is running, in real time.

Production environments are backed by a 99.9% monthly uptime SLA, a maximum of about 43.8 minutes of downtime a month. Our public status page shows live uptime and any active incidents, and we monitor the platform around the clock so issues are caught and communicated quickly.

Platform statusLive uptime & incident history
View status page
Responsible disclosure

Found something? Tell us.

We welcome reports from security researchers. If you believe you have found a vulnerability in Vortex IQ, let us know and we will work with you to confirm and resolve it quickly.

  • Email us with steps to reproduce and any supporting detail.
  • Please give us reasonable time to investigate and fix before any public disclosure.
  • Do not access, modify or delete data that is not yours, and act in good faith.

Report a security issue

Send vulnerability reports to our security inbox. If you do not get a reply, reach our main team and they will route it to the right person.

security@vortexiq.ai

Fallback: hey@vortexiq.ai

Ready to dig in?

Bring your security review. We will meet it.

Send us your questionnaire, ask for the ISO 27001 certificate and DPA, or get a walkthrough of how approvals, audit trails and rollback work on a real store.

Connect directly to the commerce platforms you run