Security
Governed by design
Vertical Flows is built so that sensitive actions stay behind explicit human approval, client access stays scoped to a single protected link, and every material step leaves a record.
1. Governed by design
Vee, the Vertical Flows assistant, is assistive rather than autonomous. It can prepare a client request, draft a checklist, or summarise what has come back, but sending a request to a client, or writing prepared work into a connected system such as Xero, requires an explicit approval step from a person on your team. Nothing is sent or written on Vee's own authority.
2. Tenant boundaries
Each firm's requests, client data, and settings are scoped to that firm's own workspace. Team members see the firms and workspaces they are actually part of, and role-based access controls what a given team member can view or change inside that workspace.
3. Protected client links
Clients complete a request through a single, unguessable access-key link rather than a shared account or public form. That link is scoped to the one request it was created for, is not listed anywhere public, and carries its own security headers to keep it isolated from the rest of the site.
4. Evidence and audit
Key steps in a request's lifecycle — preparation, sending, client responses, and review — are recorded so your firm can see what happened and when. This audit trail is designed to support accountability inside your firm, not to replace your own record-keeping obligations.
5. Provider boundaries
Connections to systems such as Xero or email providers are explicit and reviewable: Vertical Flows does not write to a connected system, or send on your behalf, without your firm first connecting that system and approving the specific action. See our Privacy Policy for how information is handled and stored.