Vexo
  • Docs
  • Pricing
  • ROI Calculator
  • Contact
  • Log In
  • Sign Up
← Back to home

Security at Vexo

Last updated: September 24, 2026

Vexo runs an agent on your machines and holds data about your GPU fleet, so you should know exactly what it collects and how it is protected. This page describes what is in place today. It also lists what we don't offer yet, so your security review doesn't have to guess.

What the agent collects

  • Hardware metrics only: GPU utilization, memory, power draw, temperature, clocks, fan speed, ECC errors, encoder and decoder load and throttling; CPU, memory and page-file usage; disk space and throughput per drive; network throughput.
  • Hardware identity: GPU and CPU model names, core count and GPU driver version.
  • GPU processes as numbers only: the process ID and GPU memory of each process using a GPU. No process names, command lines or user names.
  • Never collected: file contents, screen contents, keystrokes, browsing activity or any data your workloads process.

How the agent connects

  • Outbound only. The agent calls the Vexo server; it opens no listening port, so there is no inbound firewall rule to add.
  • Enrollment keys. Machines join a workspace only with an enrollment key an admin creates - limited to one machine, or reusable for mass deployment. It is scoped to one workspace, expires after at most a year, can be limited to a number of machines and to 300 new machines per minute, and is stored only as a hash. A key can only enroll machines, never read data. Each machine it enrolls still gets its own credential. Revoking the key stops new enrollments at once. Machines are recognised by a one-way hash of the operating system's machine ID, never the ID itself.
  • Per-agent credentials. Enrollment exchanges the token for a credential unique to that machine, and the server stores only its hash. On the machine only the agent can read it: in Vexo Desktop it is encrypted with Windows DPAPI for the signed-in user; the Windows service keeps it encrypted with DPAPI in a folder only SYSTEM and Administrators can open; on Linux it is a file only the agent's own unprivileged service account can read.
  • Short-lived access. Metric uploads use an access token that expires after 60 minutes.
  • Revocable. Revoking an agent cuts it off immediately. The action needs a one-time code sent to the admin's email.

Accounts and sign-in

  • Two-step sign-in. Every sign-in needs your password plus a one-time code sent to your verified email. A code allows three attempts and is deleted automatically after 24 hours.
  • Password storage. Passwords are stored only as salted Argon2id hashes, never in plain text. Argon2id is designed to need a lot of memory, which makes cracking with GPUs expensive.
  • Sessions. Sessions use HTTP-only, SameSite=Strict cookies, marked Secure outside local development, so page scripts can't read them and other sites can't send them. Access tokens expire after 60 minutes and refresh tokens after 30 days.

Workspace isolation and access control

  • Separate workspaces. Every workspace's agents, metrics, members and settings are scoped to that workspace. A user or agent in one workspace can't read another's data.
  • Role-based permissions. Permissions are checked on the server for every page and API call, not just by hiding buttons. For example, only permitted roles can add or revoke agents, invite members or view and change billing settings.
  • Invitation only. People join a workspace only by an invitation sent by a member with permission to invite.

Data retention

  • Metrics history is kept for 90 days, then deleted automatically.
  • Account and workspace data is kept while the account exists. See the Privacy Policy for details and your rights over your data.

What we don't offer yet

Vexo is in early access. If your review needs any of the following, tell us; it directly shapes what we build next.

  • No independent certification yet (SOC 2, ISO 27001).
  • No single sign-on (SAML or OIDC) yet. Sign-in is email, password and one-time code.
  • No exportable audit log yet.
  • The Linux agent needs RHEL 9, Debian 11, Ubuntu 20.04 or newer; RHEL 8 isn't supported yet.
  • The Windows installers aren't code-signed yet. (The Linux packages are GPG-signed - see verifying a Linux package.)
  • Vexo is hosted by us; a self-hosted or on-premises edition isn't available.

Reporting a vulnerability

If you think you've found a security issue, please report it through the contact form or by email to yolosoft.tech@gmail.com, with the steps to reproduce it. Please don't access other customers' data or disrupt the service while testing. We'll confirm we've received your report and keep you updated until it's resolved.

© Vexo by Yolosoft Technology. All rights reserved.

Docs Pricing ROI Calculator Security Contact Terms Privacy