SECURITY & TRUST
What we do today, and what we are building next.
Velantir Labs is an early-stage company. This page describes our current security and data-handling practices in plain language, and states honestly which enterprise certifications we have not yet obtained.
CURRENT PRACTICES
01 — DATA IN TRANSIT AND AT REST
Encryption by default
Traffic to Velantir is served over TLS. Data stored by the platform is encrypted at rest using the encryption provided by our infrastructure providers. Encryption keys are managed by those providers rather than held on application servers.
02 — ACCESS CONTROL
Least privilege, reviewed access
Access to production systems is limited to the small number of engineers who need it, protected by multi-factor authentication and reviewed periodically. Customer workspaces are logically separated, and internal access to customer data is limited to support and incident response.
03 — WHAT WE COLLECT
Public and licensed signals
Velantir analyses externally available signals — public social posts, news, search and other publicly accessible or licensed sources — together with the Protected Assets and keywords a customer configures. Velantir is not designed to ingest customer internal systems, private communications or special-category personal data.
04 — RETENTION
Kept as long as it is useful, then removed
Signal and alert history is retained for the period agreed in the customer contract and deleted or aggregated afterwards. Website enquiry data is retained only for as long as needed to respond to and manage the commercial conversation. Customers can request deletion of their data at any time.
05 — PRIVACY
Data minimisation as a design rule
We collect the smallest amount of personal data needed to operate the product and the sales relationship. We do not sell personal data. Requests relating to access, correction or deletion are handled through the contact detail in our Privacy Policy.
06 — CHANGE AND INCIDENT HANDLING
Reviewed changes, defined escalation
Production changes go through code review and version control. Suspected security incidents are triaged internally and affected customers are notified without undue delay in line with contractual and legal obligations.
ASSURANCE ROADMAP
We would rather state our position accurately than overstate it.
IN PROGRESS
Formal policy set and control mapping
Documenting security, access, retention and vendor-management policies against a recognised control framework.
PLANNED
Independent assurance
We intend to pursue third-party audited assurance (for example SOC 2 Type II or ISO/IEC 27001) as enterprise deployments require it. We do not hold these certifications today and do not claim them.
PLANNED
Enterprise controls
SSO/SAML, granular role-based permissions, audit logging exports and customer-selectable data residency, prioritised with early enterprise customers.
Velantir Labs does not currently hold SOC 2, ISO/IEC 27001 or equivalent third-party certification. Any statement on this page describes current practice or stated intent, not certified compliance. For security questionnaires, DPAs or architecture detail, contact us through the demo request form.
SECURITY REVIEW
Bring your security team to the conversation.
We are happy to walk your security, privacy or procurement team through how Velantir handles data before any commercial discussion.