Trust
Operational practices behind the platform. For the technical security model and its honest limits, see Security architecture.
Backup and disaster recovery
Vortalis has run a real backup-and-restore drill: a full database backup, restored into a separate scratch database, verified row-for-row with zero data corruption. That drill is local mechanism validation, not a cloud or multi-region exercise. No cloud or cross-region failover has been tested yet, and we are not going to claim otherwise until it has been.
Recent security hardening
Every human approval or denial decision is now written into the cryptographic audit chain itself, along with the reviewer's reason, so a decision and its rationale are both queryable from the tamper-evident record rather than a separate mutable table. API keys can now be rotated with a configurable grace period, so a new key takes over without an outage while the old key is automatically revoked once the window elapses. Building that rotation path surfaced and closed a real cross-tenant scoping gap in the API key management endpoints. None of this is dramatic; it is the kind of steady hardening we expect to keep doing.
Vulnerability disclosure
Report a vulnerability via security.txt (RFC 9116).
Vortalis runs on Vortalis
The first external client integrated against Vortalis's own governance contract is a real production system: MTE Software's autonomous SEO and generative-engine-optimisation agent, governed the same way any customer's agents would be. Its content, outreach, and optimisation actions are policy-checked and written to the audit chain like everything else on the platform. We run our own agents through the same governance boundary we sell.