Trust & Safety
Vendo AI operates autonomous AI agents that contact real people on your behalf. That responsibility shapes how we build: security, compliance and safe-by-design AI controls are product features, not afterthoughts.
Data security
- Encryption everywhere. All traffic is encrypted in transit (TLS 1.2+); customer data is encrypted at rest.
- Workspace isolation. Every workspace's agents, audiences, campaigns and CRM data are strictly separated. API keys are workspace-bound and can be revoked instantly.
- Hashed credentials. API keys are stored as SHA-256 hashes — we cannot read your key after creation, and neither can an attacker who obtains our database.
- Least-privilege access. 11 granular API scopes let you grant integrations exactly the access they need — see the API documentation.
Safe-by-design AI controls
- Destructive-action protocol. Any action that spends money or deletes data requires an explicit two-step preview → confirm flow. AI assistants connected via MCP must deliberately choose the execute tool after a human sees the preview.
- Billing is read-only, by design. There is no API scope that can move money. Plan changes and top-ups happen only in the authenticated portal — a leaked key can never trigger a charge.
- Human oversight. Campaign launches show recipients, channels and cost before anything is sent; every outbound touch is logged and auditable in the CRM and communications stream.
Responsible outreach
Autonomous does not mean unaccountable. All outreach through Vendo AI must comply with our Outreach & Anti-Spam Policy (CAN-SPAM, GDPR, PECR): working unsubscribe mechanisms, honest sender identity, suppression lists, and volume controls are enforced at the platform level. LinkedIn outreach respects the platform's server-side limits rather than attempting to evade them.
Privacy & compliance
- GDPR. We act as processor for the prospect data you bring and controller for your account data — details in our GDPR Compliance statement and Privacy Policy.
- Your audiences stay yours. Uploaded contact lists are stored only in your workspace — never shared, pooled or resold.
- Data deletion. You can delete agents, audiences, leads and your entire workspace at any time; deletion cascades to derived data.
Report a concern
Found a vulnerability, received unwanted outreach sent through our platform, or have a data-protection question? Write to support@vendo-ai.com — security reports are triaged with priority. See also Support.
