Skip to content
VecShieldVecShield

Security

Security is the product, so it is also the practice.

VecShield runs in your environment, calls no VecShield service, and sends no telemetry. There is very little of yours for us to lose — by design.

Responsible disclosure

Found a vulnerability in VecShield or this website? Report it privately to contact@vecshield.org. We acknowledge reports and coordinate disclosure with reporters. Do not open public issues for unpatched vulnerabilities.

Architecture

Runs in your environment

The console deploys into your VPC, Kubernetes cluster, cloud account or air-gapped datacenter. Chunks, embeddings, findings and evidence stay in infrastructure you control.

No telemetry by default

Telemetry is off by default and the console calls no VecShield service, so there is very little of your data for us to hold.

Masked by default

Sensitive values are masked; chunk text is fetched live only during explicit review, and every reveal is audited.

Safe mode

Destructive actions are blocked unless you explicitly turn safe mode off, and remediation plans require hashed approval.