Trust Center
Facts, not claims.
What Vellaci does to protect undisclosed vulnerabilities, incident records, SBOMs and security evidence. Everything on this page describes controls that exist today; certifications appear here only once obtained.
Security
Tenant isolation
Row-level security on every tenant table; permissions evaluated in Postgres and re-checked server-side before every mutation; automated cross-tenant tests run in CI.
Authentication
Email/password (≥ 12 chars), TOTP MFA with single-use recovery codes, organisation-level MFA enforcement at page and action level, SAML 2.0 / OIDC SSO with verified domains, JIT provisioning and role mapping, password login can be disabled per domain.
Authorisation
Seven roles with a seeded permission matrix, time-bound support access granted by the customer, time-limited read-only auditor access, partner access with customer-controlled maximum role, two-person approvals for high-risk operations.
Encryption
TLS 1.2+ in transit; AES-256 at rest (managed by the database/storage provider); integration secrets, webhook secrets and SSO client secrets encrypted with AES-256-GCM under a server-held key; API tokens stored as SHA-256 hashes only.
Audit logging
Append-only, hash-chained audit log per organisation with actor, entity, before/after and request context; exports carry chain verification results; CRA submissions are frozen as signed snapshots with amendment history.
Application security
Strict CSP, security headers, schema validation, SSRF guards on every customer-supplied URL, rate limiting on authentication, uploads, search and the API, signed inbound webhooks with replay protection, resource caps on SBOM parsing, no shell or code execution.
Data minimisation
Chat/pager notifications carry identifiers only unless an admin opts in; analytics carry identifiers and counts; the optional AI assistant receives allow-listed, redacted fact sheets — never attachments, source code or secrets.
Infrastructure
EU-first hosting
EU-first hosting. Database, authentication and object storage run in an EU region; the application tier runs on an EU-region serverless platform.
| Component | Region | Provider |
|---|---|---|
| Postgres database | EU (Frankfurt, eu-central-1) | Supabase |
| Object storage (SBOMs, evidence, reports, exports) | EU (Frankfurt, eu-central-1) | Supabase Storage |
| Authentication | EU (Frankfurt, eu-central-1) | Supabase Auth |
| Application / API | EU (fra1) with EU-only function execution | Vercel |
| Product analytics | EU (eu.i.posthog.com) | PostHog |
| Transactional email | EU sending region where available; content contains no vulnerability details | Resend |
| Billing | Global (card data never touches Vellaci) | Stripe |
| AI assistant (optional, opt-in per organisation) | Anthropic API; minimised fact sheets only; can be disabled entirely | Anthropic |
Dedicated single-tenant hosting (separate project, keys and region) is available on Enterprise contracts. We do not claim sovereign hosting.
Privacy
Data handling
Controller / processor
Vellaci processes customer data as a processor under a data processing agreement; product data (vulnerabilities, incidents, evidence) belongs to the customer.
Personal data
Limited to account data (name, e-mail, role, activity timestamps, IP/user agent in the audit log) and any personal data customers place in records.
Retention
Customer-configurable retention categories; CRA documentation retained ≥ 10 years by default; lapsed subscriptions keep data readable and exportable; organisation deletion has a 30-day cooling-off period with a final export.
Portability
Full organisation export (JSON per table, audit CSV, evidence index, integrity manifest) at any time; public API and CLI.
Compliance
Certifications and readiness
Vellaci operates an information-security programme aligned with SOC 2 and ISO/IEC 27001 practices (access reviews, asset inventory, change management, incident response, backup testing, vendor management, security training, risk register). No certification has been obtained yet; we do not claim one.
Responsible disclosure
Report a vulnerability in Vellaci
E-mail security@vellaci.ch or use the disclosure form. We acknowledge within 2 business days and coordinate disclosure with reporters. Machine-readable contact: /.well-known/security.txt.
Subprocessors
Who processes data on our behalf
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | EU (Frankfurt) |
| Vercel | Application hosting and CDN | EU (Frankfurt) functions; global edge network for static assets |
| Stripe | Subscription billing | EU/US (PCI DSS Level 1) |
| Resend | Transactional email | EU/US |
| PostHog | Product analytics | EU (Frankfurt) |
| Anthropic | AI assistant (only when enabled by the organisation) | US/EU API endpoints; minimised data |
| Atlassian / Linear / Slack / Microsoft / PagerDuty / GitHub / GitLab | Customer-configured integrations | As configured by the customer |
Policies
Documents available under NDA
- Threat model and security controls
- Penetration test scope and latest summary
- Incident response runbook
- Backup and disaster recovery plan (RPO/RTO)
- Business continuity for CRA deadlines
- Security questionnaire pack (CAIQ-style)
- Data processing agreement and subprocessor register
- Access review and change management procedures
Running a security review?
We share architecture details, RLS policies, test evidence and the questionnaire pack under NDA.