Access control, enforced tool by tool
Every user has a role, and every role has an explicit list of tools it may use. Your accountant can query the accounts but not read the inbox; warehouse staff can check stock but never see payroll. Permissions are verified on every request at the server — not just hidden in the interface.
Encryption and authentication
All traffic runs over HTTPS. Credentials for your connected systems are stored encrypted, requests are authenticated with signed tokens, and multi-factor authentication is available for every account. Each client's deployment is isolated from every other client's.
A full audit trail
Every query is recorded: who asked, what they asked, which tools were used, and when. Owners can review their team's activity at any time. Actions that change data — sending, updating, logging — always go through human review before anything is finalised.
Your data is never used to train AI
Your business data — invoices, emails, stock levels, customer records — is never used to train or improve any AI model, and we never sell data to anyone. AI processing is covered by a data processing agreement with our provider, with recognised UK transfer safeguards in place.
Where your data lives
Vesuvian is built and operated in the United Kingdom, and the platform is hosted on UK and EU infrastructure. We work with a small, named set of subprocessors:
| Processor | Purpose | Location |
|---|---|---|
| Anthropic PBC | AI query processing | USA (transfer safeguards in place) |
| Supabase Inc. | Database hosting | EU |
| Vercel Inc. | Application hosting | UK (London, lhr1 region) |
| Railway Corp. | Connector (MCP server) hosting | EU |
| Google LLC | OAuth sign-in, Gmail API email, and website analytics (analytics with consent) | USA (transfer safeguards in place) |
| Sentry | Error monitoring | EU |
Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Full detail, including retention periods and your rights, is in our privacy policy.
What we deliberately don’t do
- We never use your data to train or improve AI models.
- We never sell your data, to anyone, for any reason.
- We don’t store the content of files you attach to conversations — they are processed in memory and discarded once your question is answered.
- We don’t let the AI take irreversible actions on its own — anything that changes data waits for human review.
For your accountant, IT advisor, or DPO
A Data Processing Agreement (DPA) is available for every client, and we’re happy to walk your advisors through the architecture, data flows, and controls before you commit to anything.
Found a potential vulnerability? Please report it to info@vesuvian.uk — we acknowledge reports within 24 hours.