Skip to main content
Thinking about applying?See how the assessment works
All legal documents

VERTX Legal

Security and Acceptable Use Policy

Version 1.0. Effective 25 July 2026. Governed by the laws of England and Wales.

VERTX SECURITY AND ACCEPTABLE USE POLICY

Version: 1.0 Effective date: 25 July 2026 Applies to: All Clients, Contractors and users of the VERTX platform

This Policy is incorporated by reference into the VERTX Master Services Agreement (MSA) and the VERTX Independent Contractor Agreement (ICA). Breach may result in suspension, removal or legal action.


1. PLATFORM COMMUNICATIONS

1.1 Mandatory channels

Until a Placement is active and paid, all project-related communication must take place through VERTX-managed channels, meaning the Platform's messaging and dashboard. This includes:

  • scope discussions and task assignments;
  • code reviews and technical feedback;
  • handoff and deployment coordination.

Once a Placement is active and the first payment has been taken, the Client and the Contractor may work and communicate through the Client's own tools, for example Google Meet, Slack or the Client's repositories, as permitted by MSA Clause 5 and ICA Clause 6. That freedom applies to day-to-day delivery only. It never permits off-platform engagement, payment or circumvention.

1.2 Prohibited off-platform activity

You must not:

(a) move commercial or pre-Placement project communications to personal direct messages, WhatsApp, personal email, or any channel not managed by VERTX;

(b) discuss, negotiate or agree rates, fees, compensation or any other commercial term outside VERTX-managed channels. Commercial terms are agreed with VERTX only, and never between a Contractor and a Client (ICA Clause 6.5);

(c) solicit or agree any direct payment or direct engagement arrangement outside VERTX.

1.3 VERTX fallback channels

If a VERTX-managed channel is temporarily unavailable, VERTX will communicate a fallback channel. Do not assume a personal channel is authorised because a managed channel is briefly down.

1.4 Reporting

Any attempt by another party to move commercial communications or payments outside VERTX channels must be reported to VERTX immediately at hello@vertxtalent.io.


2. ACCESS CONTROLS

2.1 Principle of least privilege

Request and hold only the access needed for your current work. Do not accumulate or retain access beyond what the task requires.

2.2 Multi-factor authentication

Multi-factor authentication must be enabled on every account used for engagement work where it is supported, including source control, cloud consoles, CI/CD systems and password managers. Two-step verification is mandatory on your VERTX account.

2.3 Access revocation

Access to Client systems, repositories and credentials must be revoked promptly when a Placement ends: by the Contractor within 48 hours of the Placement concluding, and by the Client at its end.


3. CREDENTIAL AND SECRET HANDLING

3.1 No plain text

Credentials, API keys, tokens, passwords and secrets must never be shared in plain text by message, chat or email.

3.2 Secure management

Use encrypted secret management for all credentials, for example environment variables, a secret vault or a password manager. Suitable tools include AWS Secrets Manager, GCP Secret Manager, HashiCorp Vault, 1Password Teams and Bitwarden.

3.3 No secrets in code

Secrets must never be committed to any repository, including a private one. If a secret is committed by accident, rotate it immediately and notify VERTX.

3.4 Sharing between parties

Where a credential must pass between a Contractor and a Client for a legitimate engagement purpose, it must be shared by a secure method approved by VERTX.


4. DEVICE AND ENDPOINT SECURITY

4.1 Patching

Devices used for engagement work must have current operating system and software security patches applied within a reasonable time of release.

4.2 Endpoint protection

Reasonable anti-malware and endpoint protection must be enabled on every device used for engagement work.

4.3 Encryption and screen lock

Disk encryption (FileVault, BitLocker or equivalent) and an automatic screen lock must be enabled on every device used for engagement work.

4.4 Personal devices

Where a personal device is used, the same standards apply. VERTX or a Client may ask for confirmation of device compliance on a higher-security engagement.


5. CODE AND CHANGE MANAGEMENT

5.1 Pull requests

Changes to a Client codebase should be submitted by pull request with a clear description, context and testing notes. Direct pushes to main or production branches should be avoided without the Client's explicit authorisation.

5.2 Production deployments

A Contractor must not deploy to a production environment without the Client's approval, unless the engagement record expressly grants that authority.

5.3 Documentation

Significant work, decisions and changes should be recorded in the relevant issue tracker, pull request or release notes, so there is a clear audit trail.


6. AI-ASSISTED DEVELOPMENT TOOLS

6.1 The Contractor's own practice

Contractors are proficient users of AI-assisted development tools, including large language models, and maintain that proficiency as part of their own professional practice. VERTX does not train, teach or certify Contractors, and does not direct which tools a Contractor uses or how the work is performed. A Contractor reviews, validates and takes full professional responsibility for all output, including AI-assisted output, before delivery, and does not pass through unreviewed AI output (ICA Clause 5.2, MSA Clause 4.6).

6.2 Data restrictions

Do not input any of the following into an AI tool that is not approved for the purpose:

  • Client secrets, credentials or API keys;
  • Client personal data or customer data;
  • Client Confidential Information, including unpublished code, architecture detail and business data.

Where there is doubt, treat the data as confidential and obtain the Client's approval before using an AI tool with it.

6.3 Client policies

Where a Client communicates its own AI usage policy for its environment, that policy is followed. Where a Client has none, this Policy is the minimum standard.

6.4 Transparency

Where a Client asks, be open about the use of AI-assisted tools in the work, particularly for code generation.


7. DATA HANDLING

7.1 Personal data

Personal data encountered during a Placement, including a Client's customer data or employee records, must be handled in accordance with applicable data protection law and the obligations in the ICA and MSA.

7.2 Data minimisation

Access only the data needed for the task. Do not copy, download or retain Client data beyond what is necessary.

7.3 Storage

Client data must not be held on personal cloud storage, personal email or any unsecured location. Engagement data must remain accessible to VERTX and the Client through agreed channels.

7.4 Deletion after a Placement

All Client data must be deleted from personal devices and storage within 5 business days of a Placement ending, unless the Client instructs otherwise in writing. VERTX may require evidence of deletion (ICA Clause 5.6).


8. INCIDENT REPORTING

8.1 What counts as an incident

Report any of the following immediately:

  • suspected or confirmed unauthorised access to systems or data;
  • accidental exposure of credentials or secrets;
  • loss or theft of a device holding engagement data;
  • discovery of malware or a suspected attack;
  • any data breach or near miss affecting personal data.

8.2 How to report

Report through the VERTX-managed channel and by email to security@vertxtalent.io. Where personal data is affected, also notify the Client directly.

8.3 Timelines

  • Initial report: immediately on discovery.
  • Where personal data is involved, VERTX must be notified within 24 hours, so that VERTX can assess whether notification to the Information Commissioner's Office is required within 72 hours of VERTX becoming aware.
  • VERTX notifies its own cyber insurer within 72 hours of first awareness of an actual or suspected data breach.

8.4 Containment

On discovering an incident: rotate compromised credentials immediately, revoke the relevant access, and preserve evidence that may be needed for the investigation.


9. PLATFORM LOGGING, MONITORING AND TRANSPARENCY

9.1 Administrative logs

VERTX keeps administrative logs of platform activity, including communications in VERTX-managed channels and access events, for platform security, quality assurance, dispute resolution and contractual compliance. Logging is carried out in accordance with the VERTX Privacy Policy.

9.2 Communication monitoring

VERTX monitors platform communications for quality assurance, dispute resolution, detection of off-platform circumvention, and relationship health. Pattern matching is automated and flagged messages are reviewed by VERTX administrators. This monitoring is a platform service feature. It is not supervision or control of a Contractor's working methods. Contractors retain complete control over their technical approach, working hours, location, tooling and the manner in which the services are performed.

9.3 What this monitoring is not

The monitoring described in this Section is not, and must not be construed as, employment-style supervision, direction or control of a Contractor's work for the purposes of UK employment law, the off-payroll working rules, United States worker-classification law, or any equivalent regime.

9.4 Continuity

VERTX maintains automated backups of its production database through its managed hosting providers, retains the ability to redeploy the application, and follows the incident-response steps set out in Section 8.


10. IDENTITY, ACCOUNTS AND PLATFORM ACCESS

10.1 Real name and clear photograph

Every user must register and use the Platform under their real legal name and use a clear, recent photograph of themselves as their profile image. Avatars, cartoons, logos, stock images, group photographs and pseudonyms are not permitted. Misrepresenting identity, or operating under a false or borrowed identity, is a material breach of this Policy and of the applicable MSA or ICA, and is also addressed in the vetting-integrity provisions of the applicable VERTX Terms of Service.

10.2 Anti-scraping and automated access

The anti-scraping and automated-access restrictions in the applicable VERTX Terms of Service apply to all use of the Platform and are incorporated into this Policy by reference. In summary, and without limiting those provisions, you must not scrape, crawl, extract data from, frame, mirror or apply automated access to the Platform, and you may access it only through the interfaces VERTX provides. Breach permits immediate suspension and may result in legal action.


11. ENFORCEMENT

A breach of this Policy may result in:

(a) a written warning;

(b) temporary suspension of platform access;

(c) immediate termination of the Placement or the Agreement; and

(d) legal action under the applicable MSA or ICA.

Repeated attempts to bypass VERTX-managed communication channels are a material breach of the MSA and the ICA.


12. POLICY QUESTIONS

Contact security@vertxtalent.io with any question about this Policy.


VERTX TALENT LTD, vertxtalent.io Security and Acceptable Use Policy, version 1.0, 25 July 2026.

Questions about this document: privacy@vertxtalent.io