Skip to content

Vortyx security

Security for connected inbox workflows

Vortyx combines product-level controls for connected-account workflows with Google OAuth app verification, CASA Tier 2 security validation by TAC Security, and Microsoft Entra publisher verification.

ESOF Shield Certified

Encryption in transit

Encryption at rest

Server-side authorization

Workspace-scoped access

Regional workspace routing

Separated OAuth credential storage

Review-first external actions

Integration disconnect and token removal

Infrastructure as code

Managed backup/recovery controls

Security and privacy controls

Vortyx protects workspace data with authenticated access, server-side authorization, encryption in transit, and encryption at rest in managed cloud infrastructure.

Connected-account credentials are stored separately from review and task data, and access is limited to backend services that need them. When an integration is disconnected, Vortyx stops future sync and removes locally stored OAuth credentials where technically supported.

Vortyx does not store raw Gmail messages as continuity records. It stores minimized derived review artifacts, excerpts, metadata, and user-visible continuity records needed to power review, follow-up, and user-approved action workflows.

Workspace data is routed to the workspace's home region. Vortyx currently supports US and India regional backends, with a limited global routing layer for sign-in, session routing, workspace discovery, invites, and provider callbacks.

Vortyx is review-first: suggested actions, extracted next steps, and draft replies are shown for user review before external action is taken.

Verification and validation

Google OAuth app verification confirms Vortyx's OAuth consent screen and requested Google API scopes for the connected features users enable.

CASA Tier 2 validation by TAC Security provides independent security validation for Vortyx's connected inbox workflows.

Microsoft Entra publisher verification helps users and admins confirm the authenticity of the organization behind Vortyx's Microsoft identity app.

User-controlled access

  • Inbox scanning is opt-in.
  • Email checks are controlled per connected account.
  • Inbox and calendar access is scoped to user-enabled features.
  • Users review suggested actions before they become tasks.
  • Vortyx does not auto-send messages.