Product

VaultIQ

A private client vault for advisory firms. Every document, note, and meeting record for a client in one place, isolated at the database level, searchable by the people entitled to see it — and by nobody else.

Automate the retrieval, never the relationship.

Retrieval is machine work. Judgement, context, and the conversation with a client are not. VaultIQ exists to give the minutes back, not to stand between an advisor and the client they are advising.

Availability

VaultIQ is in a private pilot with one client organization. It is not generally available, it is not sold on this website, and there is no public sign-up. This page exists so that the people evaluating it — clients, partners, and platform reviewers — can read an accurate account of what the software does.

What VaultIQ does today

Built, running, and exercised against the hosted system.

Everything in this section exists in the pilot build. Nothing in it is a roadmap item wearing the present tense.

Available now:

One vault per client, isolated in the database

Each client gets a vault. Separation is enforced by row-level security in Postgres rather than by application code alone, so a query that forgets its filter returns nothing rather than someone else's client. The isolation is exercised by an automated suite against the hosted database, not only against a local copy.

Available now:

Access that mirrors how a firm actually works

Organization roles of owner, advisor, and member; a separate role on each individual vault; and visibility grants that keep advisor-private material away from staff who should not read it. An advisor demoted at the organization level is narrowed at the database level too, not merely hidden in the interface.

Available now:

Two sharing models, chosen by the firm

A firm can run in explicit mode, where every vault is shared deliberately with named people, or in a shared mode, where every active advisor in the firm is added to new vaults automatically. Which mode a firm is in is recorded on the organization, and every membership row records why it exists — created, granted by policy, or added by hand.

Available now:

Document intake and retrieval

PDF, plain-text, Markdown, and CSV sources are ingested and their text extracted for retrieval. Other formats are stored and tracked but not yet read; that gap is listed below rather than glossed over.

Available now:

Meetings, facts, and an audit trail

Meeting records, meeting items, and durable client facts live alongside the documents. Access and connector changes are written to an audit log, so the question of who saw what has an answer that does not depend on memory.

Available now:

Retention and export the client controls

Retention periods are set by the client organization rather than assumed, and a full tenant export is available to the owner. A pilot cannot begin until the owner has approved real data, acknowledged key custody, and set retention — the software refuses to treat those as defaults.

Designed, not built

What VaultIQ does not do yet.

Published in the same place and the same type size as the capabilities above, because a product page that only lists strengths is not a description — it is an advertisement.

Planned, not built:

Google Calendar scheduling from inside a vault

Booking a client meeting without leaving that client's vault, and seeing the meetings already on the calendar in context. Designed and specified. No Google connection exists in the software today — see the disclosure below.

Planned, not built:

Meeting-recording intake

Bringing recorded meeting summaries into the right client vault automatically, with the association verified before anything is filed. Specified, including the signature-verification scheme. Not built.

Planned, not built:

Bulk onboarding and source routing

Creating many client vaults at once from an existing client list, and routing a large batch of mixed documents to the right vault with a confidence threshold and a human review queue for anything ambiguous. Specified. Not built.

Planned, not built:

Text extraction for office formats

Word, Excel, and PowerPoint files are stored today but their text is not extracted, so they are not yet retrievable by content. Closing that gap is on the post-pilot list.

Integration disclosure

Google Calendar integration — planned, not active

VaultIQ does not connect to Google today. It requests no Google permissions, receives no Google user data, and stores no Google user data. There is no live authorization flow in the software, and the credentials such a flow would require are not configured.

What will be requested, and why

When the integration is enabled, VaultIQ will request the narrowest permissions that let it do the job, and only at the moment someone chooses to connect their own calendar:

https://www.googleapis.com/auth/calendar.events.readonly

Read events on the calendar of the person who connected it, so their upcoming client meetings can be shown in context inside that client's vault.

https://www.googleapis.com/auth/calendar.events

Create and update meetings that the user schedules from inside a client vault, so scheduling does not require leaving the vault and re-typing the details.

What will never be requested

  • Gmail — no mail scope is requested, and no mailbox is read
  • Google Drive — no Drive scope is requested, and no files are read
  • Google Contacts, Google Chat, and every other Workspace service
  • Any calendar other than the one belonging to the person who connects

How the connection will work

  • Each user connects their own Google account. Connecting is a choice, never a condition of using VaultIQ, and a firm can run the product with no Google connection at all.
  • Authorization tokens are encrypted with AES-256-GCM before they are written to storage, and each record is readable only by the account that created it, enforced by row-level security in the database rather than by application code alone.
  • A user can disconnect at any time from their Google account permissions page or from within VaultIQ. Disconnection is recorded, and the stored authorization stops being usable.
  • Calendar information is shown only to the people already entitled to see that client, under the same vault permissions that govern every other record. It is not shown across firms, and vault isolation applies to it exactly as it applies to documents.

Limited Use

Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data will not be used for advertising, will not be sold or transferred except as required to provide the feature the user asked for or as required by law, will not be read by humans except with the user's explicit permission, for security purposes, to comply with law, or on data that has been aggregated and made anonymous, and will not be used to develop, improve, or train generalized artificial-intelligence or machine-learning models.

The full account of how VaultIQ handles Google user data is in the Google Workspace and Google API Data section of the BSTS Privacy Policy. If the wording on this page and the wording in that policy ever disagree, the Privacy Policy is the governing statement.

Security posture

The boundary is the product.

VaultIQ holds the records a firm would least like to see in the wrong hands. The engineering reflects that, and the wording here stays inside what can actually be demonstrated.

  • Tenant isolation enforced in the database by row-level security, with an automated suite that runs against the hosted database and fails the build rather than the client.
  • Least-privilege permissions requested per capability, never a blanket connection to an account.
  • Secrets held in managed environment configuration; credentials are never committed to source control.
  • An audit log of access and connector changes, retained under the client organization's own retention settings.
  • Human approval on consequential actions, consistent with how BSTS builds everything else.

These are engineering practices, not certifications. BSTS is not an accreditation body, a certification body, or an audit firm, and nothing here implies that VaultIQ has been audited or accredited by anyone.

Operator and policies

Who runs it, and the terms it runs under.

VaultIQ is built and operated by Bevier Strategic Technology Solutions LLC. Questions about the product, the pilot, or how it handles data can be sent through the contact page.

Bevier Strategic Technology Solutions LLC · [email protected] · (404) 618-2346