Skip to main content

Security at Vertex Commercial

Protecting the Vertex Commercial platform and Customer Data

Vertex Commercial ("Vertex Commercial," "we," "us," or "our") develops and operates the Vertex Commercial CRM and operations platform for cleaning companies.

Security is part of how the Vertex Commercial platform is designed, operated, maintained, and supported.

Our security approach combines access controls, organization-level authorization, transport security, environment separation, monitoring, logging, controlled software changes, backup and recovery processes, incident management, and Customer security responsibilities.

The controls applicable to a particular Customer may depend on the Services, configuration, infrastructure, integrations, and applicable commercial agreement.

No internet-connected system can eliminate all security risk. This page describes Vertex Commercial's current security approach and should not be interpreted as a guarantee that unauthorized access, service interruption, data loss, or another security incident can never occur.

Last updated
August 12, 2026
Applies to
vertexcommercial.io
Provided by
Vertex Commercial

This page is a public security overview. It is not a certification, an audit report, a penetration-test report, a service-level agreement, or a guarantee that security incidents cannot occur.

Security Overview

1. Security Responsibilities

Security of a business software platform is a shared responsibility.

Vertex Commercial is responsible for operating and protecting the parts of the platform and infrastructure that Vertex Commercial controls.

Customers are responsible for security decisions within their own organization, including:

  • selecting appropriate Authorized Users;
  • assigning appropriate roles and permissions;
  • protecting credentials;
  • removing access when personnel no longer require it;
  • securing Customer-controlled devices;
  • securing exported data;
  • securing Customer-managed integrations;
  • determining what information is appropriate to enter into the platform;
  • protecting credentials or API access provided to third-party integrations;
  • maintaining security for systems outside Vertex Commercial's control.

Vertex Commercial provides platform-level controls, but Customer configuration and account-management decisions remain important parts of the overall security model.

Identity and Access

2. Access Control

Vertex Commercial uses access controls designed to restrict access to information and functionality according to authorization.

Access decisions may take into account:

  • Customer organization;
  • Authorized User;
  • role;
  • assigned permissions;
  • requested action;
  • relevant product context.

Users should only receive access appropriate to the responsibilities assigned to them by the Customer.

3. Role-Based Access Control

Vertex Commercial uses role-based access control to help Customers limit access to functionality and information according to operational responsibilities.

Depending on product configuration, Customers may assign different permissions to administrators, managers, operational personnel, cleaners, or other Authorized Users.

Customers are responsible for assigning roles appropriate to their organization and periodically reviewing access as personnel and responsibilities change.

4. Least Privilege

Vertex Commercial applies least-privilege principles to access under its control.

Access should be limited to the information, systems, and capabilities reasonably necessary for the relevant role or operational task.

Elevated or administrative access should not be used for routine activities where lower levels of access are sufficient.

Vertex Commercial also encourages Customers to apply the same principle when assigning permissions to their own users.

5. Organization-Level Data Access

Vertex Commercial uses organization-level authorization controls designed to restrict users to Customer data and functionality that they are authorized to access.

Application requests are evaluated in the context of the authenticated user, Customer organization, assigned permissions, and requested operation.

These controls are intended to reduce the risk of unauthorized access between Customer organizations.

6. Authentication

Vertex Commercial requires authentication for access to protected Customer functionality.

Authentication and session controls are used to help verify users and restrict unauthorized access to authenticated areas of the platform.

Customers are responsible for protecting user credentials and ensuring that accounts are assigned to appropriate individuals.

Customers should notify Vertex Commercial if they suspect that credentials or an account have been compromised.

Data Protection

7. Data in Transit

Vertex Commercial uses TLS-based transport security for supported communications between users and production Vertex Commercial services.

Transport security helps protect information against unauthorized interception while it is transmitted over supported network connections.

Vertex Commercial also expects integrations and service-to-service connections to use appropriate protected transport mechanisms where supported.

8. Stored Information

Production databases, file storage, backups, and other stored information are protected using the security controls available in the configured infrastructure and service environment.

Access to stored Customer information is subject to applicable access, authorization, infrastructure, and operational controls.

9. Secrets and Credentials

Sensitive system credentials and service secrets should be handled separately from ordinary application content and should not be intentionally exposed through public website code or Customer-facing interfaces.

Vertex Commercial applies access restrictions to operational credentials according to the needs of the relevant systems and personnel.

Customers should not submit passwords, full payment-card credentials, private API secrets, or other unnecessary authentication information through ordinary Contact, Demo, or Solution Quiz forms.

Application Security

10. Environment Separation

Vertex Commercial separates development and production environments as part of its software-development and operational practices.

Production access and production changes are treated differently from ordinary development activity.

Environment separation is intended to reduce unnecessary exposure of production systems and Customer information during development and testing activities.

Customer production data should not be copied into development environments merely for convenience.

11. Change Management

Vertex Commercial uses controlled change-management practices for production software and infrastructure changes.

Changes may involve:

  • implementation;
  • review;
  • testing;
  • deployment;
  • monitoring;
  • corrective action where necessary.

The exact process depends on the nature and risk of the change.

Material production changes should be introduced through controlled deployment processes rather than uncontrolled direct modification.

12. Secure Development

Security considerations are incorporated into development and maintenance of Vertex Commercial.

Relevant practices may include:

  • input validation;
  • authorization checks;
  • dependency management;
  • separation of environments;
  • controlled production changes;
  • error handling;
  • security review of sensitive functionality;
  • monitoring of production behavior;
  • remediation of identified security issues.

The exact security activities depend on the nature and risk of the relevant code or change.

13. Input Validation and Application Controls

Vertex Commercial uses input-validation and application-level controls intended to reduce the risk of malformed, unexpected, or unauthorized input affecting the Services.

Authorization checks are applied separately from ordinary input validation where access to protected information or actions is involved.

No validation mechanism is treated as a substitute for other layers of application and infrastructure security.

Monitoring and Logging

14. Monitoring

Vertex Commercial monitors production service availability and application errors to support operational reliability and security investigation.

Monitoring may help identify:

  • service failures;
  • unexpected errors;
  • availability issues;
  • operational anomalies;
  • security-relevant events.

Monitoring is used as one source of operational and security information.

15. Logging

Vertex Commercial records selected authentication, administrative, security, and operational activities to support accountability, troubleshooting, security investigation, and service operation.

Logging may include information such as:

  • authentication events;
  • administrative actions;
  • system events;
  • errors;
  • security-relevant events;
  • operational activity required to support the Services.

Not every user action or every field-level change is necessarily recorded.

Logging scope and retention may depend on the system, event type, infrastructure, and applicable Customer agreement.

Availability and Recovery

16. Availability and Reliability

Vertex Commercial uses operational monitoring and infrastructure processes intended to support availability and reliable service delivery.

Like other internet-based services, Vertex Commercial may experience interruptions caused by maintenance, software defects, infrastructure failures, third-party service failures, internet conditions, security events, or circumstances outside reasonable control.

Any contractual uptime commitment applies only where it is expressly included in the applicable Customer agreement.

17. Backups and Recovery

Vertex Commercial maintains backup and recovery processes appropriate to the configured production infrastructure and applicable service arrangements.

Backup and recovery processes are intended to support restoration following certain failures, operational errors, or other events affecting production information.

The exact backup scope, frequency, retention, storage architecture, and recovery process depend on the configured infrastructure and applicable Customer agreement.

18. Data Export and Account Closure

Vertex Commercial provides Customer data access, export, and deletion paths according to available product functionality and applicable contractual arrangements.

Customers are encouraged to export information they reasonably require before account closure where applicable functionality is available.

Data retention and deletion after termination are governed by the applicable commercial agreement, Data Processing Agreement where applicable, Privacy Policy, technical backup lifecycle, and applicable law.

Incident Management

19. Incident Management

Vertex Commercial maintains processes for identifying, investigating, containing, and responding to security incidents affecting systems under its control.

Incident response may include activities such as:

  • assessment;
  • containment;
  • remediation;
  • recovery;
  • investigation;
  • preservation of relevant information;
  • communication where appropriate.

The actions taken depend on the nature, scope, impact, and available information relating to the incident.

20. Security Incident Notification

Where Vertex Commercial becomes aware of a security incident or personal data breach that creates an applicable Customer notification obligation, Vertex Commercial will handle notification according to applicable law and the relevant Customer agreement or Data Processing Agreement.

Initial information may be incomplete while an incident is being investigated. Where appropriate and required, Vertex Commercial may provide additional material information as it becomes reasonably available.

21. Vulnerability Management

Vertex Commercial evaluates identified security issues affecting systems and software under its control and prioritizes remediation according to factors such as potential impact, exploitability, exposure, and operational risk.

Remediation methods may include:

  • software updates;
  • configuration changes;
  • dependency updates;
  • access restrictions;
  • infrastructure changes;
  • temporary mitigations;
  • other appropriate corrective measures.

22. Security Testing

Vertex Commercial may perform security review and testing appropriate to the nature and risk of relevant systems and software changes.

The scope and method of testing may vary depending on the component, change, infrastructure, and risk being evaluated.

This public page does not claim a specific penetration-testing frequency or independent audit schedule.

Third-Party and Payment Security

23. Dependency and Third-Party Risk

Vertex Commercial relies on third-party infrastructure and service providers for portions of its technology environment.

Security of the Vertex Commercial Services therefore includes consideration of provider capabilities, contractual arrangements, technical integrations, access requirements, and other relevant risks.

Different providers may be responsible for different portions of the underlying technical environment.

Vertex Commercial does not represent that use of a third-party provider transfers all security responsibility to that provider.

24. Payment Security

Payments for Vertex Commercial Services may be processed through third-party payment service providers and financial institutions.

Depending on the payment integration, payment credentials may be collected or processed using payment technology supplied by the relevant payment service provider.

Vertex Commercial may receive transaction identifiers, payment status, payment-method information, billing information, refund information, fraud signals, or other payment-related information necessary to administer the Customer relationship.

The exact payment-data flow depends on the payment method and configured payment integration.

Customers should not send full payment-card numbers, card security codes, or other unnecessary payment credentials to Vertex Commercial through ordinary email, Contact, Demo, or Solution Quiz forms.

25. Fraud and Abuse Prevention

Vertex Commercial may use account, technical, transaction, security, and payment-related information where reasonably necessary to prevent or investigate fraud, abuse, unauthorized access, account compromise, or other misuse of the Services.

Payment service providers may independently apply additional authentication, fraud-prevention, and risk controls according to their own legal and technical requirements.

Security or fraud controls should not be used merely to make legitimate Customer cancellation or refund requests unnecessarily difficult.

AI Security

26. AI Security and Permissions

Vertex Commercial may provide AI-assisted functionality that operates using information available within the permissions and context of an Authorized User.

AI-assisted functionality is intended to respect applicable product permissions rather than provide unrestricted access to Customer information.

Where selected AI-assisted functionality can initiate or prepare a critical operation, Vertex Commercial may require user confirmation before the operation is completed.

AI-generated output should be reviewed before it is relied upon for material business decisions.

27. AI Data Handling

Information processed through AI-assisted functionality may be handled by configured AI services according to the applicable feature, provider, Customer agreement, product configuration, and provider terms.

Vertex Commercial does not state on this page that every configured AI provider:

  • never retains Customer information;
  • never uses information for service improvement;
  • never uses information for model training;
  • processes information only in one jurisdiction.

Where an AI provider processes Customer Personal Data on behalf of Vertex Commercial, the relationship is addressed according to applicable contractual, privacy, and subprocessor requirements.

Customer Responsibilities

28. Customer-Authorized Integrations

Customers may connect Vertex Commercial to third-party services.

Security of an integration depends partly on the third-party service, credentials, permissions, configuration, and Customer decisions involved.

Customers are responsible for:

  • authorizing appropriate integrations;
  • limiting permissions where supported;
  • protecting integration credentials;
  • disabling integrations that are no longer required;
  • evaluating the security and privacy practices of third-party services they choose.

Vertex Commercial is responsible for the security of the Vertex Commercial-controlled portion of an integration, but does not control the independent systems of a third-party provider.

29. Employee and Operational Access

Vertex Commercial applies access restrictions to internal or operational access under its control according to role and business need.

Access to production information should be limited to authorized purposes such as:

  • operating the Services;
  • support;
  • security investigation;
  • maintenance;
  • resolving technical issues;
  • performing authorized Customer requests;
  • complying with lawful obligations.

Vertex Commercial personnel should not access Customer information merely because technical access may be possible.

30. Confidentiality

Individuals authorized by Vertex Commercial to access non-public Customer information are expected to be subject to appropriate confidentiality responsibilities or equivalent obligations.

Confidential information should be used only for legitimate business, operational, support, security, or legal purposes.

Additional confidentiality obligations may apply through Customer agreements.

31. Customer Security Responsibilities

Customers have an important role in protecting their Vertex Commercial environment.

Customers should:

  • use individual user accounts;
  • protect account credentials;
  • avoid credential sharing;
  • assign the minimum permissions reasonably required;
  • review administrative access;
  • remove users who no longer require access;
  • secure devices used to access Vertex Commercial;
  • protect exported information;
  • use secure integrations;
  • review suspicious account activity;
  • notify Vertex Commercial of suspected unauthorized access;
  • apply appropriate human review to sensitive AI-assisted actions.

Vertex Commercial cannot protect Customer systems, devices, credentials, or third-party services that are outside Vertex Commercial's control.

32. Security and Privacy of Customer Data

Customer Data remains subject to the contractual, privacy, security, and data-processing terms applicable to the Customer's use of Vertex Commercial.

Vertex Commercial does not acquire ownership of Customer Data merely because it is processed through the Services.

Information about controller and processor roles, subprocessors, international processing, privacy rights, retention, export, and deletion is available in the Data Processing Information and Privacy Policy.

33. Security of Data After Export

Security protections provided inside the Vertex Commercial platform may no longer apply after information is exported, downloaded, copied, transferred, or otherwise moved into Customer-controlled or third-party systems.

Customers are responsible for protecting exported information according to their own security and privacy obligations.

Compliance Status

34. Security and Compliance Status

Vertex Commercial maintains security practices appropriate to its current Services and operating environment.

Vertex Commercial does not currently claim SOC 2 certification.

Vertex Commercial does not currently claim ISO 27001 certification.

Vertex Commercial does not claim PCI DSS certification through this page.

Vertex Commercial does not represent that the platform is automatically compliant with every law or regulatory framework applicable to every Customer.

Compliance requirements may depend on the Customer's industry, location, data, workflows, configuration, and contractual requirements.

Where a Customer requires a specific regulatory or certification framework, the requirement should be reviewed during procurement before regulated data is introduced into the Services.

35. HIPAA-Regulated Information

Organizations that require HIPAA-regulated processing must complete a separate legal, technical, and contractual review before using Vertex Commercial for protected health information.

The availability of ordinary security functionality does not itself establish that a particular Customer use case satisfies HIPAA requirements.

36. Payment Card Compliance

Payment-card security obligations depend on the payment architecture and responsibilities of Vertex Commercial, the Customer, and the relevant payment service provider.

Vertex Commercial does not use this page to claim PCI DSS certification.

Where payment-card functionality is used, the applicable payment architecture and compliance responsibilities should be evaluated according to the actual integration and relevant payment-provider requirements.

Security Reporting

37. Security Reviews and Due Diligence

Customers, enterprise procurement teams, payment service providers, and other authorized parties may request reasonable information about Vertex Commercial security practices as part of a legitimate due-diligence process.

Certain security information may not be appropriate for unrestricted public disclosure.

Depending on the nature of the request, additional information may be provided subject to appropriate confidentiality, verification, contractual, or security restrictions.

Requests may be sent to [email protected].

38. Report a Security Concern

If you believe you have identified a security issue affecting Vertex Commercial, please report it responsibly to [email protected].

Please include enough information for Vertex Commercial to understand and investigate the issue.

Do not include unnecessary Customer Personal Data, full payment-card credentials, passwords, or unrelated confidential information in the initial report.

Security research must not involve unauthorized access, destruction, disruption, social engineering, data exfiltration, or access to another Customer's information.

Vertex Commercial does not publish a monetary bug-bounty commitment through this page.

39. Security Incidents Affecting Customers

If an incident affecting Customer information creates an applicable notification obligation, Vertex Commercial will communicate according to the relevant contractual and legal requirements.

Vertex Commercial may use the Customer's designated administrative or security contacts for such communications.

Customers are responsible for maintaining current contact information for individuals who should receive important account and security communications.

40. No Absolute Security Guarantee

Security is an ongoing risk-management process.

Vertex Commercial works to protect its Services and Customer Data using controls appropriate to the current platform and operating environment, but no software, network, infrastructure provider, authentication method, encryption mechanism, monitoring system, or security process can guarantee that all security incidents will be prevented.

Customers should evaluate Vertex Commercial in the context of their own security, legal, contractual, and regulatory requirements.

Contact

41. Security Contact

Questions about Vertex Commercial security practices or legitimate security due-diligence requests may be directed to:

Vertex Commercial, Entity ID 0008102431, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States.

Vertex CommercialEntity ID: 00081024311209 Mountain Road Pl NESte NAlbuquerque, NM 87110United States[email protected]+1 (505) 298-3585https://vertexcommercial.io

Last updated: August 12, 2026

Questions about this document

Vertex Commercial1209 Mountain Road Pl NESte NAlbuquerque, NM 87110United States[email protected]+1 (505) 298-3585