SECURITY & TRUST

What we do today, and what we are building next.

Velantir Labs is an early-stage company. This page describes our current security and data-handling practices in plain language, and states honestly which enterprise certifications we have not yet obtained.

CURRENT PRACTICES

01 — DATA IN TRANSIT AND AT REST

Encryption by default

Traffic to Velantir is served over TLS. Data stored by the platform is encrypted at rest using the encryption provided by our infrastructure providers. Encryption keys are managed by those providers rather than held on application servers.

02 — ACCESS CONTROL

Least privilege, reviewed access

Access to production systems is limited to the small number of engineers who need it, protected by multi-factor authentication and reviewed periodically. Customer workspaces are logically separated, and internal access to customer data is limited to support and incident response.

03 — WHAT WE COLLECT

Public and licensed signals

Velantir analyses externally available signals — public social posts, news, search and other publicly accessible or licensed sources — together with the Protected Assets and keywords a customer configures. Velantir is not designed to ingest customer internal systems, private communications or special-category personal data.

04 — RETENTION

Kept as long as it is useful, then removed

Signal and alert history is retained for the period agreed in the customer contract and deleted or aggregated afterwards. Website enquiry data is retained only for as long as needed to respond to and manage the commercial conversation. Customers can request deletion of their data at any time.

05 — PRIVACY

Data minimisation as a design rule

We collect the smallest amount of personal data needed to operate the product and the sales relationship. We do not sell personal data. Requests relating to access, correction or deletion are handled through the contact detail in our Privacy Policy.

06 — CHANGE AND INCIDENT HANDLING

Reviewed changes, defined escalation

Production changes go through code review and version control. Suspected security incidents are triaged internally and affected customers are notified without undue delay in line with contractual and legal obligations.

ASSURANCE ROADMAP

We would rather state our position accurately than overstate it.

IN PROGRESS

Formal policy set and control mapping

Documenting security, access, retention and vendor-management policies against a recognised control framework.

PLANNED

Independent assurance

We intend to pursue third-party audited assurance (for example SOC 2 Type II or ISO/IEC 27001) as enterprise deployments require it. We do not hold these certifications today and do not claim them.

PLANNED

Enterprise controls

SSO/SAML, granular role-based permissions, audit logging exports and customer-selectable data residency, prioritised with early enterprise customers.

Velantir Labs does not currently hold SOC 2, ISO/IEC 27001 or equivalent third-party certification. Any statement on this page describes current practice or stated intent, not certified compliance. For security questionnaires, DPAs or architecture detail, contact us through the demo request form.

SECURITY REVIEW

Bring your security team to the conversation.

We are happy to walk your security, privacy or procurement team through how Velantir handles data before any commercial discussion.