VECTIFORM
Trust center · updated July 28, 2026

Clear controls. Honest status.

Vectiform documents what is operating today, what customers control, and what is still in progress. Your brand language and customer data remain private to your studio.

Customer control

Network learning

Only confirmed dimension facts—such as material, color, size and finish—can contribute. Product names, brand voice, prices and customer data never enter the shared pool.

Existing studios: change the setting at any time in Settings & Brand → Privacy & data. New studios are asked during onboarding; no API call is required.

Data rights

Export and deletion

Owners can download a complete JSON export in Settings. A self-service deletion request begins a seven-day safety window, can be cancelled during that window, and requires verified owner access.

Live rows and stored images are deleted after approval; encrypted rolling backups age out within 30 days.

Security and resilience

ControlCurrent postureCustomer evidence
Transport and edgeTLS, HSTS, DDoS protection, security headers and tenant-scoped authorization on Cloudflare.Public status and response headers.
AuthenticationEmail/password and passwordless links; Google/Microsoft OIDC becomes available when production provider credentials are connected. Platform console supports authenticator MFA and keeps the platform key as recovery.Sign-in provider status is shown rather than implied.
Payment dataStripe hosts card collection. Vectiform does not store raw card numbers.Stripe-hosted checkout and signed webhooks.
BackupsDaily encrypted backups with 30-day rolling retention; auth credentials are scrubbed from portable exports.Platform reliability center and restore procedures.
Recovery targetsRTO target: 24 hours. RPO target: 24 hours. These are operating targets, not contractual guarantees unless written into an order form.Owner incident and backup guide.
IncidentsNo material customer-data security incident is published as of July 28, 2026. Material incidents will be posted here with scope and remediation.This dated incident history.

AI processing

Cloudflare Workers AI and Anthropic may process scans only to provide the requested classification. Suggestions stay drafts until a studio approves them. Vectiform does not claim that foundation models train on customer data.

Review every subprocessor →

Legal and privacy

The DPA describes roles, instructions, subprocessors, security measures, deletion and incident notice. It is a product template, not a substitute for customer legal review.