Skip to content
VectorHub

Agents your security team can sign off on

The blocker on enterprise agent deployments is rarely the model. It is that nobody can answer which systems the agent can reach, who granted that, and what it did last Tuesday. VectorHub answers all three.

Governance

Three questions, answerable on demand

These are the questions that stop pilots from becoming deployments.

01

What can this agent reach?

Every agent’s access is an explicit allowlist of connectors and tools, visible in one screen. Not “whatever that API key happens to permit”.

02

Who granted it?

Connection creation, key minting and scope changes are all attributable administrative events with an actor and a timestamp.

03

What did it do?

Every tool call is logged with arguments, outcome and calling key: including the calls that were denied, which are often the interesting ones.

Controls

Built for a security review

The controls a review will ask about, present by default rather than added on request.

Encrypted credential vault

Secrets are encrypted with envelope encryption, per-tenant data keys and a managed KMS root. Plaintext exists only in memory for the duration of an outbound call.

Scoped, revocable keys

Every key is bound to a connector and tool allowlist with an optional expiry. Revocation takes effect on the next request, with no cache to wait out.

Isolated execution

Connector calls run in per-tenant sandboxes with egress allowlists, so one tenant's traffic cannot reach another tenant's resources.

Complete audit trail

Who called what, with which arguments, from which key, at what time. Exportable to your SIEM with configurable retention.

Least-privilege by default

New keys start with no access. Scopes are added deliberately rather than trimmed back from a permissive default.

Regional data handling

Choose where credentials and logs are stored. EU and US regions are available, with custom residency for enterprise deployments.

Deployment

Managed, VPC or fully self-hosted

Where the gateway runs is your decision, and it does not change how it behaves.

Managed

We run it. Regional credential stores, EU or US, with residency controls.

In your VPC

The gateway runs in your cloud account; we manage the release channel and connector packages.

Self-hosted

Fully air-gapped operation with signed connector bundles delivered on your schedule.

Included

On the enterprise plan

The parts that make a platform deployable at scale rather than usable by one team.

  • SSO via SAML, with SCIM user provisioning
  • Role-based access control across teams and environments
  • Audit log export with configurable retention
  • Data residency in EU, US or a region you nominate
  • Private connectors for internal APIs
  • 99.95% uptime SLA and a named support engineer
  • Security questionnaire, architecture docs and pentest summaries
FAQ

Enterprise questions

Can VectorHub run inside our own infrastructure?

Yes. Enterprise deployments run in your VPC or fully self-hosted, with the same connector catalog delivered as signed packages. Credentials never leave your boundary.

How do we control which teams can reach which systems?

Role-based access control governs who can create connections and who can mint keys against them. A team can be permitted to use a connection without being able to view or export its credential.

What does the audit trail cover?

Every tool call, with its arguments, calling key, agent label, latency and outcome, plus every administrative action: connection created, key minted, scope changed, credential rotated. Exportable to your SIEM with configurable retention.

Where is data stored?

EU and US regions are available on standard plans, with custom residency for enterprise. Credential stores are regional and are never replicated across a residency boundary.

How do you handle procurement and security review?

We provide architecture documentation, a completed security questionnaire, penetration test summaries and a named engineer for the review. Talk to us early and it usually moves quickly.

Start the security review early

Tell us your deployment model and residency requirements and we will send the architecture documentation the same week.

No credit card required · Free tier available · Self-host on request