Read-only connections
An API key with read scope, or an OAuth grant with the least it can ask for. Vesqo checks each permission on connect and writes to a tool only through an automation you made.
Security and data
Vesqo reads a company's most sensitive numbers: who pays, what they pay, what broke, what customers wrote. This page says what it reads and what it does not, where that lives, who can see it, and how long it stays. The privacy policy and the terms are the contract; this is the plain account of it.
An API key with read scope, or an OAuth grant with the least it can ask for. Vesqo checks each permission on connect and writes to a tool only through an automation you made.
The application and its database run at Hetzner Online GmbH in the European Economic Area (Falkenstein, Germany). Backups are encrypted, nightly, and stay in the EU.
Every question, answer, automation run, change of settings and support access is in the workspace's audit log, by whom, when. Yours to read and export.
Each connection reads the least that finds a signal: subscriptions, invoices and payments from Stripe, never card numbers; hourly error counts, new issues and releases from Sentry, never event payloads or source maps; hourly counts and each customer's daily activity from PostHog, never recordings or profiles; releases from GitHub, never code. Each integration's page lists what it takes, and the connect page in the app says what it needs before you paste anything.
Credentials are encrypted at rest with keys held outside the database, used only to read the data described for your workspace, refreshed when the tool requires, and deleted the moment you disconnect the source or the workspace. You can also withdraw the grant from the tool's own settings at any time, which stops Vesqo reading it.
One application and one Postgres database, at Hetzner Online GmbH in the European Economic Area (Falkenstein, Germany). Connections use TLS. Every workspace's data is isolated at the database level, with Postgres row-level security policies that read which workspace the request is for: a query in one workspace cannot reach another's rows. Encrypted nightly backups are stored in the EU and keep a deleted workspace's copy for up to 30 days, then it is gone from those too.
The members you invite, with the role you give each. Vesqo's own access is limited to what running the service needs: the plan, the sources connected, the members. We open a workspace's contents only to provide support or fix a fault, read-only, for 7 days at most: either an owner grants it from Settings, or we open it with a reason that is written to the workspace's audit log and mailed to its owners; either way the owners can end it at any time. Sign-in sessions expire 30 days after sign-in; passwords are stored as hashes. The operator console has a second factor.
The signals are written by rules in Vesqo's own code. No customer data goes to a model to find them. When you ask Ask Vesqo a question, the question and the data it needs to answer are sent to Anthropic's API under its commercial terms: not used to train models, and normally deleted within 30 days. Every question and answer is in the audit log. News headlines about the companies that pay you are sorted by topic the same way, and are public to begin with.
Account and workspace data stay while the workspace exists. The hourly and daily series read from your sources (error counts, activity, key events) are kept for 90 days unless a longer window is agreed; your customers' history (subscriptions, issues, conversations, deals, releases) is not pruned. A workspace without a plan is paused and keeps its data for 90 days, then it is deleted. Deleting a workspace removes its events, accounts, signals, conversations, automations and audit log from active systems immediately, and from backups within 30 days. Everything can be exported from Settings first, as JSON.
Your connected tools receive only the requests needed to read your data and, when you set an automation to do so, the note or message you asked Vesqo to write. Sub-processors change with 30 days' notice by email to workspace owners.
For your account, workspace settings and billing, Vesqo is the controller. For the data your connected tools send about your customers, you are the controller and Vesqo is your processor; the data processing terms in the terms of service are the Article 28 contract between us. We help with data subject requests (a customer's data can be found by account and deleted or exported in the product), and should a breach put your rights or your customers' at risk we notify you without undue delay. The privacy policy has the lawful bases, the retention periods and the rights in full.
Vesqo has no SOC 2 report or ISO 27001 certificate. Ask privacy@vesqo.app anything this page does not answer; security reports go to the same address.
The demo is Farol Jobs, a made-up job board with a bad release in it, every screen open. Ask it anything. Then connect your own.
Vesqo would like to count visits with Google Analytics. Google's cookies are set only if you say yes, and the site is the same either way. Cookie notice