Trust Center

Facts, not claims.

What Vellaci does to protect undisclosed vulnerabilities, incident records, SBOMs and security evidence. Everything on this page describes controls that exist today; certifications appear here only once obtained.

All systems operational · Live status and incident history

Security

Tenant isolation

Row-level security on every tenant table; permissions evaluated in Postgres and re-checked server-side before every mutation; automated cross-tenant tests run in CI.

Authentication

Email/password (≥ 12 chars), TOTP MFA with single-use recovery codes, organisation-level MFA enforcement at page and action level, SAML 2.0 / OIDC SSO with verified domains, JIT provisioning and role mapping, password login can be disabled per domain.

Authorisation

Seven roles with a seeded permission matrix, time-bound support access granted by the customer, time-limited read-only auditor access, partner access with customer-controlled maximum role, two-person approvals for high-risk operations.

Encryption

TLS 1.2+ in transit; AES-256 at rest (managed by the database/storage provider); integration secrets, webhook secrets and SSO client secrets encrypted with AES-256-GCM under a server-held key; API tokens stored as SHA-256 hashes only.

Audit logging

Append-only, hash-chained audit log per organisation with actor, entity, before/after and request context; exports carry chain verification results; CRA submissions are frozen as signed snapshots with amendment history.

Application security

Strict CSP, security headers, schema validation, SSRF guards on every customer-supplied URL, rate limiting on authentication, uploads, search and the API, signed inbound webhooks with replay protection, resource caps on SBOM parsing, no shell or code execution.

Data minimisation

Chat/pager notifications carry identifiers only unless an admin opts in; analytics carry identifiers and counts; the optional AI assistant receives allow-listed, redacted fact sheets — never attachments, source code or secrets.

Infrastructure

EU-first hosting

EU-first hosting. Database, authentication and object storage run in an EU region; the application tier runs on an EU-region serverless platform.

ComponentRegionProvider
Postgres databaseEU (Frankfurt, eu-central-1)Supabase
Object storage (SBOMs, evidence, reports, exports)EU (Frankfurt, eu-central-1)Supabase Storage
AuthenticationEU (Frankfurt, eu-central-1)Supabase Auth
Application / APIEU (fra1) with EU-only function executionVercel
Product analyticsEU (eu.i.posthog.com)PostHog
Transactional emailEU sending region where available; content contains no vulnerability detailsResend
BillingGlobal (card data never touches Vellaci)Stripe
AI assistant (optional, opt-in per organisation)Anthropic API; minimised fact sheets only; can be disabled entirelyAnthropic

Dedicated single-tenant hosting (separate project, keys and region) is available on Enterprise contracts. We do not claim sovereign hosting.

Privacy

Data handling

Controller / processor

Vellaci processes customer data as a processor under a data processing agreement; product data (vulnerabilities, incidents, evidence) belongs to the customer.

Personal data

Limited to account data (name, e-mail, role, activity timestamps, IP/user agent in the audit log) and any personal data customers place in records.

Retention

Customer-configurable retention categories; CRA documentation retained ≥ 10 years by default; lapsed subscriptions keep data readable and exportable; organisation deletion has a 30-day cooling-off period with a final export.

Portability

Full organisation export (JSON per table, audit CSV, evidence index, integrity manifest) at any time; public API and CLI.

Compliance

Certifications and readiness

Vellaci operates an information-security programme aligned with SOC 2 and ISO/IEC 27001 practices (access reviews, asset inventory, change management, incident response, backup testing, vendor management, security training, risk register). No certification has been obtained yet; we do not claim one.

Responsible disclosure

Report a vulnerability in Vellaci

E-mail security@vellaci.ch or use the disclosure form. We acknowledge within 2 business days and coordinate disclosure with reporters. Machine-readable contact: /.well-known/security.txt.

Subprocessors

Who processes data on our behalf

SubprocessorPurposeLocation
SupabaseDatabase, authentication, storageEU (Frankfurt)
VercelApplication hosting and CDNEU (Frankfurt) functions; global edge network for static assets
StripeSubscription billingEU/US (PCI DSS Level 1)
ResendTransactional emailEU/US
PostHogProduct analyticsEU (Frankfurt)
AnthropicAI assistant (only when enabled by the organisation)US/EU API endpoints; minimised data
Atlassian / Linear / Slack / Microsoft / PagerDuty / GitHub / GitLabCustomer-configured integrationsAs configured by the customer

Policies

Documents available under NDA

  • Threat model and security controls
  • Penetration test scope and latest summary
  • Incident response runbook
  • Backup and disaster recovery plan (RPO/RTO)
  • Business continuity for CRA deadlines
  • Security questionnaire pack (CAIQ-style)
  • Data processing agreement and subprocessor register
  • Access review and change management procedures

Running a security review?

We share architecture details, RLS policies, test evidence and the questionnaire pack under NDA.