Security
Built to be trusted with undisclosed vulnerabilities.
Vellaci holds sensitive data: exploit details, unreleased fixes, incident evidence, architecture information. This page describes the controls in place. We do not claim certifications we do not hold.
Tenant isolation
Every tenant-owned table carries the organisation identifier and is protected by Postgres row-level security. Permissions are evaluated in the database for each role; the application re-checks them server-side before every mutation.
Access control
Seven roles (owner, admin, security, compliance, engineer, auditor, external advisor) with server-enforced permissions. Organisation-level MFA enforcement (TOTP). Vellaci support access is explicit, time-bound, granted by the customer and fully logged.
Data protection
EU-hosted Postgres and storage. Evidence, SBOMs and reports live in private buckets with random object paths and short-lived signed URLs; no public buckets. Integration credentials are encrypted with AES-256-GCM using a key held only by the server.
Auditability
An append-only audit log records actor, organisation, action, entity, before/after state, timestamp and request context. CRA revisions are immutable and hashed.
Application security
Strict Content-Security-Policy and security headers, schema validation on every input, MIME/extension/magic-byte checks and size limits on uploads, signature-verified Stripe and GitHub webhooks with replay protection, no arbitrary code or shell execution.
Third-party data
Vulnerability intelligence queries send package identifiers only. Analytics never receive vulnerability descriptions, evidence content or secrets. AI features are opt-in and labelled.
Responsible disclosure
Report vulnerabilities in Vellaci to security@vellaci.ch or through the disclosure form. We acknowledge within two business days, coordinate publication with reporters and publish a security.txt under RFC 9116.
Subprocessors
Supabase (database, auth, storage — EU region), Stripe (billing), Resend (transactional email), PostHog EU (product analytics), Vercel or equivalent (hosting). A current register is provided in customer agreements.
Go deeper
- Guide
Coordinated vulnerability disclosure under the CRA: policy, intake and security.txt
Annex I Part II requires manufacturers to enforce a coordinated vulnerability disclosure policy and publish a contact address. What the policy must contain, how to align it with ISO/IEC 29147 and 30111, how to run intake, and how it connects to Article 14.
- Docs
Security architecture
Isolation, encryption, audit chain, threat model summary.
- Docs
Security settings
MFA, SSO, approvals, tokens, auditors, retention, deletion.
Questions about your security review?
We share architecture details, RLS policies and test evidence under NDA.