Skip to main content
Vexa is built for the buyer whose question is not “which cloud?” but “how do we run this without a cloud?” — banks, healthcare, government, and anyone whose meeting content cannot transit a vendor’s infrastructure. This page collects what a security review asks for.

Deployment posture

  • Self-hosted, single perimeter. Every service — capture bots, transcription, storage, agents, the web workbench — runs on infrastructure you control (Deployment, Kubernetes). Services bind to loopback; the gateway is the one front door, with an optional pre-auth edge layer — per-IP rate throttle, auto-ban of repeat offenders, and static IP allow/deny — behind a GUARD_ENABLED kill switch, on by default on every self-hosted path (compose and Helm both ship it enabled; set GUARD_ENABLED=false or gateway.guard.enabled=false to opt out). See Configuration → Gateway edge protection.
  • Self-hosted STT, no egress. Pair the stack with the self-hosted transcription unit — bundled GPU or CPU — and your own LLM endpoint, and the audio path never calls out: ✅ Docker Compose · Lite, 🟡 Kubernetes, where the chart does not yet expose TRANSCRIPTION_MODEL as a value and you set it on the meeting-api and terminal Deployments via extraEnv, which the chart’s own known boundaries state. We have not run an install on a genuinely disconnected network, so we do not claim one: what a procurement review can hold us to is self-hosted with no egress, not a certified air gap.
  • Bring your own models. LLM and speech-to-text endpoints are configuration (Configuration); credential terms are documented in Model credentials & licensing.
  • Own, don’t rent. Apache-2.0. Transcripts and derived knowledge are Markdown in a git repo you hold — leaving the product does not orphan the data.

Trust model

  • Agents are untrusted by design. They are prompt-injectable, so they enforce nothing themselves. Every agent runs in an isolated, ephemeral container, scoped to only the workspaces it was granted — agents never run in the control plane. See Identity & trust.
  • Agent network egress is your cluster’s policy today. The stack ships no egress control: there is no NetworkPolicy in the Helm chart, Compose agents share the stack’s Docker network, and the default agent toolset includes Bash, WebSearch and WebFetch. If agents must not reach the internet, enforce it with a Kubernetes NetworkPolicy or a firewall on the Docker host.
  • Trusted vs untrusted input. You, in chat, write to the workspace directly (git is the undo). Untrusted input — an email, a web page — runs propose-only: the agent suggests, a human approves, trusted code applies. Irreversible effects (send, order) are always gated. See Governance.
  • Identity at the edge. The gateway derives identity from your API key server-side; internal services trust only the gateway’s asserted identity, not client-supplied fields.

Audit artifacts in the repo

If you are the person who has to sign off on this dependency, Architecture review is the guided read of that table — what each artifact proves, what it does not, and what running it costs — without asking us.

Known gaps (honest)

At-rest encryption for workspaces, transcripts, and tokens is planned, not shipped — today you bring your own disk/volume encryption. Mid-call bot control endpoints are not wired in the open-core stack. Track both on the status page. Agent containers have unrestricted outbound network access unless your cluster restricts it (see the trust model above).

Reporting a vulnerability

Follow SECURITY.md — report privately to the maintainer contact listed there; please do not open public issues for security reports.