Security & Trust

How VERTIQ protects your project data, in plain terms.

Last updated: July 22, 2026

Your work stays yours. VERTIQ processes your project documents and uploads solely to provide the service. The commitments below describe how we operate, and become contractually binding once we enter into a Mutual NDA and, where applicable, a Data Processing Agreement.

1. We never train AI on your data

VERTIQ does not use your project data, documents, or uploads to train general-purpose AI models, and we do not authorize our service providers to do so, without your explicit prior written consent. Some documents may be processed through Google Cloud and Vertex AI for analysis; under Google Cloud's applicable service terms, Google does not use customer data to train or fine-tune its AI/ML models without the customer's prior permission or instruction.

2. Encryption and infrastructure

We apply industry-standard technical measures, including:

  • Encryption in transit (HTTPS)
  • Provider-managed encryption at rest
  • Authentication and project-scoped access controls
  • Time-limited signed URLs for private stored files

3. Limited and authorized access

Your content is handled by automated systems to deliver the requested features. VERTIQ personnel do not routinely access it. A VERTIQ account can access a project through the application only when it has been explicitly added as a project collaborator. Limited infrastructure-level access may still be required for security incident response, legal compliance, or service recovery. Your data is never sold, made public, or shared with unrelated third parties.

4. Deletion on request

You can request deletion of your data at any time, and we action deletion requests promptly and can confirm in writing. If an evaluation ends, we delete or return your data within thirty (30) days once that is confirmed in writing. Copies retained in routine backups are removed on their normal cycle, and some records may be retained where required by law.

5. Third-party and collaborative project data

AEC projects are collaborative, and documents often originate from architects, engineers, and partner firms. You stay in control of what you share:

  • You do not need to upload full deliverables. VERTIQ needs only the specific inputs for the credits you want to run.
  • You can redact or remove identifying details before uploading.
  • You choose the project, and evaluations run under a signed mutual NDA with the protections described above.
  • You remain responsible for having the rights or permission to upload materials, including any belonging to collaborating firms. Our agreements protect that material once it reaches us; they do not by themselves grant permission to share a third party's work.

6. Sub-processors and data location

We use a small set of established service providers (including Google Cloud Platform, Stripe, Vercel, and Sentry) to operate VERTIQ. Each processes data only to support the applicable service, under obligations no less protective than our own. The current list is maintained in our Privacy Policy. Data may be processed in the United States or other countries in accordance with applicable data protection requirements.

7. GDPR and data processing

For customers subject to the GDPR, we act as a data processor on your documented instructions. A Data Processing Agreement is available on request. Where transfers outside the EEA rely on the European Commission's Standard Contractual Clauses, the applicable Module and Annexes are completed and signed by the parties. We notify you without undue delay of any personal data breach affecting your data.

8. Agreements

A Mutual Non-Disclosure Agreement and Data Processing Agreement are available on request for evaluations and engagements. See also our Privacy Policy and Terms of Service.

9. Contact

For security questions, data processing terms, or a copy of our agreements, contact us at admin@everpoint.net.