Security and trust
VendOrca protects your program data with workspace isolation, encryption, role-based access, an append-only change record and read-only agent access. For how we handle personal data, read the Privacy Policy and the Terms of Service.
On this page
Your data stays in your workspace
Each customer's program lives in its own workspace. Every record and every agent token belongs to exactly one workspace, and nothing in one workspace is visible from another. Workers see only their own records. Suppliers see only their own invoices.
Your data is encrypted in transit (TLS) and at rest.
Access follows the user's role
Every user has one role, and the role decides what they can see and do. A role change applies on the next request. A deactivated user loses access from their next request, including any agent tokens they issued, and their history is kept. See Roles and permissions.
VendOrca has no passwords. People sign in with Google, or with a single-use sign-in link emailed to them.
Changes are recorded, not overwritten
VendOrca keeps an append-only record of changes. Configuration applies, approvals and AI proposals are recorded, and those records can't be edited or removed in the app.
Your business records follow the same rule. A change to an assignment or to the configuration adds a new version. The earlier version is kept. Recorded time entries and invoices can't be edited or deleted in the app. See Changes add records.
AI changes need a person to apply them
AI in VendOrca drafts changes, and a person decides whether to apply them. When a Program Admin describes a configuration change, VendOrca produces a proposal with a diff, a validation result and a simulation. Nothing changes until an admin reviews it and selects Apply. The Ask VendOrca assistant is read-only: it answers questions and never changes a record or a setting.
Agent access is read-only and revocable
When you connect an AI agent or a script over MCP or the REST API:
- Every operation reads. An agent can't create, change, approve or delete anything, and can't change roles, tokens or configuration.
- A token acts as the person who issued it. It reaches only what that person can already see in the app, and a role change narrows it on the next request.
- People issue tokens only in their own name. Nobody, admins included, can issue, see or revoke someone else's token.
- The token value is shown once. VendOrca doesn't keep a usable copy.
- Every token expires. The default is 90 days and the maximum is 365.
- Revoking a token stops it on the next request. A Program Admin can also stop all agent access in the workspace at once.
- Personal data is left out unless the token was issued with the Personal data scope.
- Calls are recorded against the person who issued the token.
See How agent access stays safe.
VendOrca never holds your money
VendOrca doesn't move money. It holds no client funds, no card details and no bank credentials. Invoices go to your business systems, through a direct integration or a CSV export, and your own payment run pays them. On self-serve plans, your VendOrca subscription is handled by an external payment provider acting as merchant of record, so your card details go to that provider and not to VendOrca.
Privacy and data protection
VendOrca's legal commitments on data protection, including GDPR, are in the Terms of Service. A Data Processing Addendum is available on request. The Privacy Policy explains what personal data we process, why, and your rights over it. Contact details are on the Support page.