Product
VaultIQ
A private client vault for advisory firms. Every document, note, and meeting record for a client in one place, isolated at the database level, searchable by the people entitled to see it — and by nobody else.
Automate the retrieval, never the relationship.
Retrieval is machine work. Judgement, context, and the conversation with a client are not. VaultIQ exists to give the minutes back, not to stand between an advisor and the client they are advising.
Availability
VaultIQ is in a private pilot with one client organization. It is not generally available, it is not sold on this website, and there is no public sign-up. This page exists so that the people evaluating it — clients, partners, and platform reviewers — can read an accurate account of what the software does.
What VaultIQ does today
Built, running, and exercised against the hosted system.
Everything in this section exists in the pilot build. Nothing in it is a roadmap item wearing the present tense.
One vault per client, isolated in the database
Each client gets a vault. Separation is enforced by row-level security in Postgres rather than by application code alone, so a query that forgets its filter returns nothing rather than someone else's client. The isolation is exercised by an automated suite against the hosted database, not only against a local copy.
Access that mirrors how a firm actually works
Organization roles of owner, advisor, and member; a separate role on each individual vault; and visibility grants that keep advisor-private material away from staff who should not read it. An advisor demoted at the organization level is narrowed at the database level too, not merely hidden in the interface.
Two sharing models, chosen by the firm
A firm can run in explicit mode, where every vault is shared deliberately with named people, or in a shared mode, where every active advisor in the firm is added to new vaults automatically. Which mode a firm is in is recorded on the organization, and every membership row records why it exists — created, granted by policy, or added by hand.
Document intake and retrieval
PDF, plain-text, Markdown, and CSV sources are ingested and their text extracted for retrieval. Other formats are stored and tracked but not yet read; that gap is listed below rather than glossed over.
Meetings, facts, and an audit trail
Meeting records, meeting items, and durable client facts live alongside the documents. Access and connector changes are written to an audit log, so the question of who saw what has an answer that does not depend on memory.
Retention and export the client controls
Retention periods are set by the client organization rather than assumed, and a full tenant export is available to the owner. A pilot cannot begin until the owner has approved real data, acknowledged key custody, and set retention — the software refuses to treat those as defaults.
Designed, not built
What VaultIQ does not do yet.
Published in the same place and the same type size as the capabilities above, because a product page that only lists strengths is not a description — it is an advertisement.
Google Calendar scheduling from inside a vault
Booking a client meeting without leaving that client's vault, and seeing the meetings already on the calendar in context. Designed and specified. No Google connection exists in the software today — see the disclosure below.
Meeting-recording intake
Bringing recorded meeting summaries into the right client vault automatically, with the association verified before anything is filed. Specified, including the signature-verification scheme. Not built.
Bulk onboarding and source routing
Creating many client vaults at once from an existing client list, and routing a large batch of mixed documents to the right vault with a confidence threshold and a human review queue for anything ambiguous. Specified. Not built.
Text extraction for office formats
Word, Excel, and PowerPoint files are stored today but their text is not extracted, so they are not yet retrievable by content. Closing that gap is on the post-pilot list.
Integration disclosure
Google Calendar integration — planned, not active
VaultIQ does not connect to Google today. It requests no Google permissions, receives no Google user data, and stores no Google user data. There is no live authorization flow in the software, and the credentials such a flow would require are not configured.
What will be requested, and why
When the integration is enabled, VaultIQ will request the narrowest permissions that let it do the job, and only at the moment someone chooses to connect their own calendar:
https://www.googleapis.com/auth/calendar.events.readonlyRead events on the calendar of the person who connected it, so their upcoming client meetings can be shown in context inside that client's vault.
https://www.googleapis.com/auth/calendar.eventsCreate and update meetings that the user schedules from inside a client vault, so scheduling does not require leaving the vault and re-typing the details.
What will never be requested
- Gmail — no mail scope is requested, and no mailbox is read
- Google Drive — no Drive scope is requested, and no files are read
- Google Contacts, Google Chat, and every other Workspace service
- Any calendar other than the one belonging to the person who connects
How the connection will work
- Each user connects their own Google account. Connecting is a choice, never a condition of using VaultIQ, and a firm can run the product with no Google connection at all.
- Authorization tokens are encrypted with AES-256-GCM before they are written to storage, and each record is readable only by the account that created it, enforced by row-level security in the database rather than by application code alone.
- A user can disconnect at any time from their Google account permissions page or from within VaultIQ. Disconnection is recorded, and the stored authorization stops being usable.
- Calendar information is shown only to the people already entitled to see that client, under the same vault permissions that govern every other record. It is not shown across firms, and vault isolation applies to it exactly as it applies to documents.
Limited Use
Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data will not be used for advertising, will not be sold or transferred except as required to provide the feature the user asked for or as required by law, will not be read by humans except with the user's explicit permission, for security purposes, to comply with law, or on data that has been aggregated and made anonymous, and will not be used to develop, improve, or train generalized artificial-intelligence or machine-learning models.
The full account of how VaultIQ handles Google user data is in the Google Workspace and Google API Data section of the BSTS Privacy Policy. If the wording on this page and the wording in that policy ever disagree, the Privacy Policy is the governing statement.
Security posture
The boundary is the product.
VaultIQ holds the records a firm would least like to see in the wrong hands. The engineering reflects that, and the wording here stays inside what can actually be demonstrated.
- Tenant isolation enforced in the database by row-level security, with an automated suite that runs against the hosted database and fails the build rather than the client.
- Least-privilege permissions requested per capability, never a blanket connection to an account.
- Secrets held in managed environment configuration; credentials are never committed to source control.
- An audit log of access and connector changes, retained under the client organization's own retention settings.
- Human approval on consequential actions, consistent with how BSTS builds everything else.
These are engineering practices, not certifications. BSTS is not an accreditation body, a certification body, or an audit firm, and nothing here implies that VaultIQ has been audited or accredited by anyone.
Operator and policies
Who runs it, and the terms it runs under.
VaultIQ is built and operated by Bevier Strategic Technology Solutions LLC. Questions about the product, the pilot, or how it handles data can be sent through the contact page.
Bevier Strategic Technology Solutions LLC · [email protected] · (404) 618-2346