Security and privacy controls
Vortyx protects workspace data with authenticated access, server-side authorization, encryption in transit, and encryption at rest in managed cloud infrastructure.
Connected-account credentials are stored separately from review and task data, and access is limited to backend services that need them. When an integration is disconnected, Vortyx stops future sync and removes locally stored OAuth credentials where technically supported.
Vortyx does not store raw Gmail messages as continuity records. It stores minimized derived review artifacts, excerpts, metadata, and user-visible continuity records needed to power review, follow-up, and user-approved action workflows.
Workspace data is routed to the workspace's home region. Vortyx currently supports US and India regional backends, with a limited global routing layer for sign-in, session routing, workspace discovery, invites, and provider callbacks.
Vortyx is review-first: suggested actions, extracted next steps, and draft replies are shown for user review before external action is taken.