1. Security by design
Veltris IO is designed around least-privilege access, controlled environments, auditability, and secure software-development practices. Security controls may vary by product tier and deployment model.
2. Encryption
Data transmitted to Veltris IO services is intended to be protected using modern transport encryption such as TLS. Where supported by the applicable service architecture, data at rest is protected using industry-standard encryption mechanisms.
3. Access controls
Administrative access is restricted according to role and operational need. Enterprise plans may include additional identity and access features such as SSO, role-based permissions, and audit controls.
4. Monitoring and incident response
We use operational monitoring and security practices intended to identify, investigate, and respond to suspicious activity or service incidents. Where required, affected customers are notified in accordance with applicable agreements and law.
5. SOC 2
Security reviews and compliance programs may evolve as Veltris IO grows. References to SOC 2 on this website should not be interpreted as a representation that a specific SOC 2 audit has been completed unless a current report or formal certification is made available to the customer.
6. Responsible disclosure
If you believe you have identified a security issue affecting Veltris IO, please contact us through our contact page and include enough information for our team to investigate. Please do not include secrets or customer data in an initial report.