Skip to content
VecShieldVecShield

Security & Compliance Console

Govern the memory your AI retrieves from.

The VecShield Security & Compliance Console is a customer-hosted console for the vector and RAG infrastructure you already run. It registers your stores, assesses what's inside them, tracks every finding to a decision, and produces evidence with its own coverage stated — so a reviewer knows what was examined, not just what was found.

The lifecycle

  1. 1

    Inventory

    Register the stores you run — managed, self-hosted or forgotten — with their connector kind, owner and environment.

  2. 2

    Assessment

    Examine collections for personal, health, payment and credential data, and record how much of each was inspected.

  3. 3

    Case

    Every finding becomes a case with an owner, a decision and the counter-signals that argue against it.

  4. 4

    Action

    Erasure, redaction and re-embedding proposals, with destructive actions blocked while safe mode is on.

  5. 5

    Evidence

    An export that states who concluded what, over which stores, for which period — and what remained open.

What the console covers

Inventory and connectors

Register managed and self-hosted vector stores, including pgvector, Pinecone, Qdrant, Weaviate, Milvus, Chroma, Redis, OpenSearch and MongoDB, with owner and environment recorded.

Assessment with stated coverage

Detect PII, PHI, cardholder data and secrets in embeddings and chunks. Segments that were sampled or not scanned stay visible instead of being reported as clean.

RAG integrity

Check collections for prompt-injection content, embedding anomalies, missing provenance and cross-tenant data bleed.

DSAR, erasure and re-embedding

Locate a data subject's records across stores and propose erasure, redaction or re-embedding, with plan-hashed approvals before anything runs.

Access auditing and safe mode

Values are masked by default; every reveal is recorded in a tamper-evident audit trail. Destructive actions stay blocked while safe mode is on.

Evidence and deployment

Export evidence mapped to GDPR, HIPAA, PCI-DSS and more. The console deploys via Docker, Kubernetes/Helm, Terraform or air-gapped, with telemetry off by default.

See it against your own architecture.

A 30-minute technical walkthrough of the console, with your connector kinds on screen.