Security

Built to be trusted with undisclosed vulnerabilities.

Vellaci holds sensitive data: exploit details, unreleased fixes, incident evidence, architecture information. This page describes the controls in place. We do not claim certifications we do not hold.

Tenant isolation

Every tenant-owned table carries the organisation identifier and is protected by Postgres row-level security. Permissions are evaluated in the database for each role; the application re-checks them server-side before every mutation.

Access control

Seven roles (owner, admin, security, compliance, engineer, auditor, external advisor) with server-enforced permissions. Organisation-level MFA enforcement (TOTP). Vellaci support access is explicit, time-bound, granted by the customer and fully logged.

Data protection

EU-hosted Postgres and storage. Evidence, SBOMs and reports live in private buckets with random object paths and short-lived signed URLs; no public buckets. Integration credentials are encrypted with AES-256-GCM using a key held only by the server.

Auditability

An append-only audit log records actor, organisation, action, entity, before/after state, timestamp and request context. CRA revisions are immutable and hashed.

Application security

Strict Content-Security-Policy and security headers, schema validation on every input, MIME/extension/magic-byte checks and size limits on uploads, signature-verified Stripe and GitHub webhooks with replay protection, no arbitrary code or shell execution.

Third-party data

Vulnerability intelligence queries send package identifiers only. Analytics never receive vulnerability descriptions, evidence content or secrets. AI features are opt-in and labelled.

Responsible disclosure

Report vulnerabilities in Vellaci to security@vellaci.ch or through the disclosure form. We acknowledge within two business days, coordinate publication with reporters and publish a security.txt under RFC 9116.

Subprocessors

Supabase (database, auth, storage — EU region), Stripe (billing), Resend (transactional email), PostHog EU (product analytics), Vercel or equivalent (hosting). A current register is provided in customer agreements.

Questions about your security review?

We share architecture details, RLS policies and test evidence under NDA.