SECURITY & CONFIDENTIALITY

Security & Confidentiality Statement

This Statement explains Vortivex’s current staffing security practices, contractor confidentiality expectations, client responsibilities, and important limitations.

Effective date: June 22, 2026   |   Last updated: June 22, 2026

1. Purpose and Scope

This Security & Confidentiality Statement describes Vortivex LLC’s current public commitments and allocation of responsibilities for its IT staffing and contractor-coordination services.

This is not a certification. Vortivex does not currently claim SOC 2, ISO 27001, HIPAA certification, PCI certification, or guaranteed protection against every security incident. This Statement does not replace a signed Master Services Agreement, confidentiality agreement, Business Associate Agreement, or client-specific security addendum.

2. Vortivex’s Current Service Model

Vortivex provides staffing and contractor coordination. It screens and introduces independent IT professionals for possible client engagements. Vortivex does not currently operate as the client’s managed security provider, system administrator, hosting provider, or owner of client infrastructure unless a future signed agreement expressly expands that scope.

3. Screening and Candidate Evaluation

Before presenting a technician for an opportunity, Vortivex’s intended screening process includes:

The client also interviews and evaluates proposed technicians. Screening reduces risk but cannot guarantee future conduct, performance, or complete accuracy of all third-party information.

4. Contractor Confidentiality Expectations

Contractors assigned through Vortivex are expected to:

5. Contractor Work Environment

Unless a client provides equipment or a written engagement requires otherwise, contractors are expected to maintain their own suitable work environment, including:

Vortivex does not promise to purchase or reimburse contractor equipment, internet service, utilities, or workspace unless agreed in writing.

6. Client Responsibilities

Because the client owns and administers its environment, the client is responsible for:

7. Access and Least Privilege

Vortivex recommends that clients provide only the minimum access required for an assigned role and use client-controlled access methods. Access should be unique, attributable, time-limited where practical, monitored, and revocable.

Contractors must not attempt to exceed granted permissions, bypass technical controls, or access unrelated information. Unexpected or excessive access should be reported to the client and Vortivex.

8. Authentication and Credentials

Where available and required by the client, Vortivex expects use of MFA. Credentials should be delivered through client-approved secure methods and stored only in client-approved systems. Credentials must not be included in public forms or ordinary unencrypted messages.

The client remains responsible for account issuance, authentication policies, credential rotation, access review, and revocation.

9. Website and Business-System Security

The Vortivex website is delivered using Cloudflare and HTTPS. Public website forms are processed through Formspree, and business email is handled through Google Workspace. Vortivex uses reasonable account-access controls appropriate to its current stage.

These third parties maintain their own systems, terms, security measures, and privacy practices. No third-party service eliminates all risk.

10. Security Incident Reporting

Clients, applicants, and contractors should promptly report suspected security or confidentiality incidents involving Vortivex or an active engagement to info@vortivex.ai.

A report should include, where safely available:

Do not include passwords, active authentication codes, or unnecessary sensitive data in the initial email.

11. Incident Coordination

When Vortivex becomes aware of a potential incident, it may take reasonable steps such as notifying the client, preserving relevant records, requesting suspension of contractor activity, supporting access revocation, gathering facts, and cooperating with authorized advisers or authorities.

The client remains responsible for incident response within its systems, including containment, forensic investigation, legal analysis, breach notification, restoration, and regulator or affected-person communications, unless a signed agreement assigns a specific responsibility to Vortivex.

12. Healthcare, Dental, and Protected Health Information

Healthcare or dental staffing does not automatically make every engagement subject to the same HIPAA obligations. The actual functions and access determine whether protected health information is involved and whether Vortivex or a contractor may be treated as a business associate or subcontractor.

Vortivex will evaluate HIPAA-related engagements case by case. Before a contractor is permitted to create, receive, maintain, or transmit protected health information, the parties may need:

Vortivex may decline or delay an engagement until appropriate safeguards and written terms are in place.

13. Data Minimization

Vortivex seeks to collect only information reasonably needed for staffing requests, applicant evaluation, contractor onboarding, payment administration, legal compliance, and business records. Public forms should not be used to send passwords, patient information, client datasets, bank credentials, or government identification documents.

14. Retention and Disposal

Vortivex retains applicant, client, contractor, payment, and engagement information only as reasonably necessary for business, legal, tax, staffing, security, and dispute-resolution purposes. Information should be deleted, returned, anonymized, or securely disposed of when no longer needed and when no legal or contractual retention requirement applies.

15. No Absolute Security Guarantee

No organization, person, network, platform, or security control can guarantee complete protection. Vortivex commits to reasonable practices appropriate to its current role and information, but does not promise that incidents, errors, outages, unauthorized access, or malicious activity can never occur.

16. Continuous Improvement

Vortivex expects to update its screening, contracting, onboarding, access, incident, and vendor practices as the business grows and as client requirements change. Public statements will be revised when material practices change.

17. Contact

Security or confidentiality questions may be sent to:

Vortivex LLC
Email: info@vortivex.ai
Website: https://vortivex.ai