1. Purpose and Scope
This Security & Confidentiality Statement describes Vortivex LLC’s current public commitments and allocation of responsibilities for its IT staffing and contractor-coordination services.
2. Vortivex’s Current Service Model
Vortivex provides staffing and contractor coordination. It screens and introduces independent IT professionals for possible client engagements. Vortivex does not currently operate as the client’s managed security provider, system administrator, hosting provider, or owner of client infrastructure unless a future signed agreement expressly expands that scope.
3. Screening and Candidate Evaluation
Before presenting a technician for an opportunity, Vortivex’s intended screening process includes:
- Review of the applicant’s resume and stated experience.
- A structured interview.
- A technical assessment appropriate to the stated skill level or role.
- Identity verification.
- Reference verification.
The client also interviews and evaluates proposed technicians. Screening reduces risk but cannot guarantee future conduct, performance, or complete accuracy of all third-party information.
4. Contractor Confidentiality Expectations
Contractors assigned through Vortivex are expected to:
- Sign written confidentiality and contractor terms before beginning an assignment.
- Use client and Vortivex information only for authorized engagement purposes.
- Not disclose, copy, retain, photograph, download, transmit, or reuse confidential information except as authorized.
- Protect credentials and never share passwords through unauthorized channels.
- Access only systems, records, accounts, and data necessary for assigned work.
- Follow documented client policies, escalation paths, and acceptable-use rules.
- Promptly report suspected unauthorized access, credential exposure, data loss, phishing, malware, or other security concerns.
- Return or securely delete client information when instructed and when an engagement ends, subject to lawful record-retention requirements.
5. Contractor Work Environment
Unless a client provides equipment or a written engagement requires otherwise, contractors are expected to maintain their own suitable work environment, including:
- Reliable internet service appropriate for the role.
- A reasonably private and professional work area.
- Equipment capable of performing the assigned work.
- Reasonable safeguards against unauthorized viewing or access by household members or other third parties.
- Compliance with client-required endpoint, remote-access, authentication, and communication tools.
Vortivex does not promise to purchase or reimburse contractor equipment, internet service, utilities, or workspace unless agreed in writing.
6. Client Responsibilities
Because the client owns and administers its environment, the client is responsible for:
- Determining what access a contractor requires and approving that access.
- Creating unique accounts and avoiding shared credentials where reasonably possible.
- Applying least-privilege access and limiting administrative rights.
- Configuring MFA, VPN, VDI, RMM, remote desktop, identity, endpoint, network, cloud, and other controls.
- Maintaining backups, logging, monitoring, patching, licensing, incident-response plans, and security policies.
- Providing role-specific instructions, permitted-use rules, and escalation contacts.
- Monitoring contractor activity within the client environment.
- Disabling or revoking access promptly when no longer required or when an engagement ends.
- Determining and satisfying legal and regulatory obligations applicable to its data and systems.
7. Access and Least Privilege
Vortivex recommends that clients provide only the minimum access required for an assigned role and use client-controlled access methods. Access should be unique, attributable, time-limited where practical, monitored, and revocable.
Contractors must not attempt to exceed granted permissions, bypass technical controls, or access unrelated information. Unexpected or excessive access should be reported to the client and Vortivex.
8. Authentication and Credentials
Where available and required by the client, Vortivex expects use of MFA. Credentials should be delivered through client-approved secure methods and stored only in client-approved systems. Credentials must not be included in public forms or ordinary unencrypted messages.
The client remains responsible for account issuance, authentication policies, credential rotation, access review, and revocation.
9. Website and Business-System Security
The Vortivex website is delivered using Cloudflare and HTTPS. Public website forms are processed through Formspree, and business email is handled through Google Workspace. Vortivex uses reasonable account-access controls appropriate to its current stage.
These third parties maintain their own systems, terms, security measures, and privacy practices. No third-party service eliminates all risk.
10. Security Incident Reporting
Clients, applicants, and contractors should promptly report suspected security or confidentiality incidents involving Vortivex or an active engagement to info@vortivex.ai.
A report should include, where safely available:
- The date and approximate time.
- The affected client, account, system, or device.
- What was observed.
- Whether credentials, personal information, confidential information, or regulated data may be involved.
- Actions already taken.
- A reliable contact method for follow-up.
Do not include passwords, active authentication codes, or unnecessary sensitive data in the initial email.
11. Incident Coordination
When Vortivex becomes aware of a potential incident, it may take reasonable steps such as notifying the client, preserving relevant records, requesting suspension of contractor activity, supporting access revocation, gathering facts, and cooperating with authorized advisers or authorities.
The client remains responsible for incident response within its systems, including containment, forensic investigation, legal analysis, breach notification, restoration, and regulator or affected-person communications, unless a signed agreement assigns a specific responsibility to Vortivex.
12. Healthcare, Dental, and Protected Health Information
Healthcare or dental staffing does not automatically make every engagement subject to the same HIPAA obligations. The actual functions and access determine whether protected health information is involved and whether Vortivex or a contractor may be treated as a business associate or subcontractor.
Vortivex will evaluate HIPAA-related engagements case by case. Before a contractor is permitted to create, receive, maintain, or transmit protected health information, the parties may need:
- A Business Associate Agreement or subcontractor BAA.
- Client-approved access methods and safeguards.
- Role-specific confidentiality and HIPAA obligations.
- Appropriate incident and breach-notification terms.
- Confirmation that involved vendors and tools are suitable for the intended use.
- Insurance and legal review appropriate to the engagement.
Vortivex may decline or delay an engagement until appropriate safeguards and written terms are in place.
13. Data Minimization
Vortivex seeks to collect only information reasonably needed for staffing requests, applicant evaluation, contractor onboarding, payment administration, legal compliance, and business records. Public forms should not be used to send passwords, patient information, client datasets, bank credentials, or government identification documents.
14. Retention and Disposal
Vortivex retains applicant, client, contractor, payment, and engagement information only as reasonably necessary for business, legal, tax, staffing, security, and dispute-resolution purposes. Information should be deleted, returned, anonymized, or securely disposed of when no longer needed and when no legal or contractual retention requirement applies.
15. No Absolute Security Guarantee
No organization, person, network, platform, or security control can guarantee complete protection. Vortivex commits to reasonable practices appropriate to its current role and information, but does not promise that incidents, errors, outages, unauthorized access, or malicious activity can never occur.
16. Continuous Improvement
Vortivex expects to update its screening, contracting, onboarding, access, incident, and vendor practices as the business grows and as client requirements change. Public statements will be revised when material practices change.
17. Contact
Security or confidentiality questions may be sent to:
Vortivex LLC
Email: info@vortivex.ai
Website: https://vortivex.ai