AI that acts on your store, with guardrails built in.
Vortex IQ can act on commerce workflows, so trust is part of the product. Writes follow least-privilege access and human approval by default. Audit trails, staging and rollback apply where the connected platform and workflow support them.
Security is a default, not an add-on.
Four principles hold up everything we build. They apply to your data at rest, your data in motion, and every action an agent takes on your behalf.
Certified ISO 27001
Our information security management system is independently certified to ISO/IEC 27001: the global standard for managing risk across people, process, and technology.
Independently auditedEncrypted, in transit & at rest
Data is encrypted in transit with TLS and at rest in our cloud infrastructure. Secrets and credentials are stored in managed key vaults, never in plain text.
TLS + at-rest encryptionLeast-privilege access
Agents and people get the narrowest scopes that get the job done, nothing more. Access is role-based, time-bound and revocable, and we only request the store permissions we need.
Scoped & revocableUK & EU GDPR aligned
We process personal data in line with UK GDPR and the EU GDPR, with a clear lawful basis, data-subject rights honoured, and a Data Processing Agreement available on request.
UK GDPR + EU GDPRKeep production writes inside your controls.
An agent can detect a problem and draft work. Human approval is the default for production writes, while bounded automation is enabled only for an explicitly agreed workflow.
The agent proposes scoped work in plain English. A person reviews production writes unless bounded automation has been explicitly enabled for that workflow.
Who proposed it, who approved it, what changed and when: every Action is logged immutably, so you always have a defensible record of what happened.
Supported workflows preserve a recovery path before the write. The rollback method depends on the platform and change type.
Vortex Apps provides staging and restore points for supported commerce-platform workflows, so your team can review the available recovery path before deployment.
Tested by an independent security firm, not just our own team.
Vortex IQ undergoes independent penetration testing by SecureLayer7 Technologies, using a Grey Box methodology aligned with OWASP Top 10, OWASP ASVS 4.0.2, NIST SP 800-115 and PTES. The most recent assessment ran from 2 to 4 June 2025 and identified seven findings, one critical, one high and five low. Every finding was remediated and confirmed closed during the retest.
The paperwork your security team will ask for.
We only claim what we hold today: ISO 27001 certification, GDPR alignment, and BigCommerce Elite Partner status. SOC 2 is genuinely in progress, not yet complete, and we say so rather than implying otherwise. We will not overstate our posture; if a framework is on the roadmap rather than in place, we will say so.
Read our security & data-protection policies.
The policies and documents that govern how we build, run and secure the platform. Each is maintained and dated, and available here in full.
See how the platform is running, in real time.
Production environments are backed by a 99.9% monthly uptime SLA, a maximum of about 43.8 minutes of downtime a month. Our public status page shows live uptime and any active incidents, and we monitor the platform around the clock so issues are caught and communicated quickly.
Found something? Tell us.
We welcome reports from security researchers. If you believe you have found a vulnerability in Vortex IQ, let us know and we will work with you to confirm and resolve it quickly.
- Email us with steps to reproduce and any supporting detail.
- Please give us reasonable time to investigate and fix before any public disclosure.
- Do not access, modify or delete data that is not yours, and act in good faith.
Report a security issue
Send vulnerability reports to our security inbox. If you do not get a reply, reach our main team and they will route it to the right person.
security@vortexiq.aiFallback: hey@vortexiq.ai
Bring your security review. We will meet it.
Send us your questionnaire, ask for the ISO 27001 certificate and DPA, or get a walkthrough of how approvals, audit trails and rollback work on a real store.