Free tool How audit-ready is your organisation? Get your score in 3 minutes. Take the readiness check

Security & trust

Audit data is sensitive. We treat it that way.

Audits contain certificates, financial records, staff details and supplier information. Here is how Vexsai protects them, and how you can review our security for yourself.

Encrypted connections

Vexsai is served only over HTTPS with TLS 1.2 or newer, and browsers are told to always use HTTPS (HSTS).

Password-protected audit links

Each audit link is unique, protected by a password you set, and can be given an expiry date. Respondents only see the audit they were invited to.

Role-based access

Decide who in your team can build audits, assign them, view reports and manage users.

Audit trail

Answers, uploaded files and changes are time-stamped and attributed to the person who made them.

Protected infrastructure

Our website is served through Cloudflare's network, which filters malicious requests and absorbs attacks before they reach our servers.

Your data stays yours

You own your audit content. We use it only to provide the service and never sell it. AI analysis runs only on audits you choose to analyse.

Security reviews

Have a security questionnaire for us?

Many customers need to assess their vendors before signing, and we expect you to assess us too. Send us your security questionnaire and we'll complete it as part of your evaluation.

Request a security review

Responsible disclosure

If you believe you've found a security vulnerability in Vexsai, please email [email protected] with "Security" in the subject. Include steps to reproduce, and give us a reasonable time to fix the issue before sharing it publicly. We'll acknowledge your report and keep you updated.

Please don't access other people's data, disrupt the service, or run automated scans against production systems.

Related

More about how we handle data