Skip to content
Vertex Lake
Menu

Trust

Trust is a diagram, a table and a verifier. Not a promise.

The archive runs where you choose. The portal runs on ours. The line between them is narrow by design, and this page draws it: what crosses, what never can, how the software proves itself before it runs, and the documents an auditor reads.

Where it runs, and who it talks to

The deployment: one archive on your network, browsers beside it, and two outbound peers Inside your network: the VX Drive appliance with its database, blob store and processing; browsers on the same network reach it. Outbound, and only these: the vendor's registry, pulled from on the schedule you set; the vendor's portal, for the daily check-in and licence refresh. Dotted, and only if you configure them: a timestamp authority and hosted AI providers. Your network, or wherever you choose to run it VX Drive the database the files, checksummed processing and the models the audit chain backups, to where you choose browsers scanners, folders Vertex Lake the registry: signed releases pulled on your schedule the portal: licence, check-in five fields, once a day a timestamp authority — only a hash hosted AI — only what you switch on

Inside the frame: the archive and the browsers, scanners and folders on the same network. Outbound, and only these: our registry, for releases on your schedule; our portal, for the daily check-in and licence refresh. Dotted, and only if you configure them: a timestamp authority and hosted AI providers.

What leaves your archive

WhatWhat it carries
The daily check-inonce a day, to the portalThe instance's id, the version it runs, its update channel, the checksum of its licence and whether its last refresh installed one. Five fields; nothing of yours.
The licence refreshwith the check-inNothing goes out but the credential; the current licence comes back when a newer one exists.
The registry pullwhen an update is dueNothing: it downloads the release, verified against the release key before it runs, on the schedule you set.
A timestamp authorityonly if you configure oneA hash of an audit anchor, a custody record or a report. Never content.
Hosted AIonly for the stages and workspaces you switch onWhat you allowed, with an audited, content-free record of every call. Off by default; never for a workspace under a barrier or in evidence mode; never for the visual index or text recognition.
Backupson your scheduleEncrypted copies, to destinations you choose; the keys stay in your recovery kit, and every copy opens with stock tools and a key you hold — never through us.
SIEM forwardingonly if you configure itThe audit chain's own lines, to your receiver, with a bearer token you set.

What Vertex Lake never sees

A document, a page, a word of recognised text, a search, a question or an answer. Your users, their names or their sign-ins. Your audit trail. There is no route in the product by which any of these could reach us: the appliance's only calls to us are the daily check-in with its licence refresh and the image pulls.

What the portal holds is your account: the organisation's name, billing address and tax id; the names and email addresses of the people you invite; the licences issued; the hashes of the credentials issued; each appliance's check-ins; orders and invoices as Stripe reports them; support conversations and enquiries; the address and time of each sign-in, checkout and enquiry attempt for two days (a rate limit's memory); a sender's address on an enquiry for thirty days; and our own audit chain of every act on your account, which you can read.

How the software proves itself before it runs

Every release image carries three signatures: two by our release key, held in a hardware security module and never on a disk — one in the layout the appliance's podman checks under a strict policy before it runs anything, one as a Sigstore bundle for cosign 3 — and one bound to the identity of our release workflow, with a signed software bill of materials beside it. The appliance installer the portal serves comes with its digest and its Sigstore bundle. Licences are signed by a second key in the same vault, and the product verifies every licence with the public half built into the software. Our release workflow reaches the vault through a federated identity; no secret lives in the source repository.

With cosign 3 and the public key that ships in the appliance's policy, which is this one:

-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEtPE1gym3qe4VaBR3xaWTLrlQapQ2
9JaW4+qXz/9MO/erGOmFHQYDVldYZv+mi2kqDspWZQQbCwGks+/kPz9eGQ==
-----END PUBLIC KEY-----
cosign verify --key release-signing.pub registry.vertexlake.com/vxdrive-server:1.0.0

And the keyless signature, against the workflow's identity:

cosign verify --certificate-identity-regexp '^https://github.com/pm64/vxdrive/.github/workflows/release.yml@refs/tags/v' --certificate-oidc-issuer https://token.actions.githubusercontent.com registry.vertexlake.com/vxdrive-server:1.0.0

Before any of that, the code itself: the archive's services are written in a memory-safe language, so the buffer overflows and use-after-free behind so many advisories cannot be written into them, and what they borrow that is not — the PDF renderer, the recognisers, the model runtimes — runs in a sandbox with no network, only the files it was handed, and a budget of time and memory; the model engines run under a confinement of their own, with one port to bind and nothing to connect to; the backup client and the database dump run outside the sandbox in a scrubbed environment, and we say so in the hardening guide rather than round it up.

A licence file verifies with the product's own tool and the key printed on your licence page; an audit chain export verifies with a verifier that ships with the software and needs nothing from us. The appliance's runbook has the whole procedure, the key's fingerprint and what a mismatch looks like.

What auditors read

The assurance pack ships with the software and is published here from the same files, so you can read before you evaluate what an auditor reads after.

  • Security questionnaire answers

    The questions vendor-security reviews ask, answered plainly: deployment, data, access, audit, AI, backups, the vendor's services.

  • Hardening guide

    What the operator does to make the controls hold: transport, egress, the operator directories, sealed data, deployment locks.

  • Shared responsibility

    What the product guarantees in shipped code, what the operator does, and what the vendor's own services cover.

  • Accessibility conformance

    The WCAG 2.2 conformance skeleton for the product, self-assessed, with the behaviours that matter listed.

  • Licence register

    Every third-party component in the product and this site, by licence, with what is shipped and how.

Sub-processors of the portal

ProviderWhat forWhere
Microsoft AzureThe portal, its database, the registry's storage, the signing keys, transactional emailWest US 2
StripePayments, invoices, tax; the card never touches our systemsStripe's own regions

The archive itself has no sub-processor: it runs where you put it, and reaches only what the table above says.

Reporting a vulnerability

Write to security@vertexlake.com. We answer within two working days and keep you told until it is fixed. Fixes ship as releases; the appliance applies them by policy.