Trust Center
Security you can verify.
We are an early-stage company and are transparent about where our security program stands today.
SOC 2 Type IIIn progress
ISO 27001In progress
Encryption in transit & at restIn place
Metadata-only collectionBy design
Data residency optionsOn request
Audit loggingIn place
What we collect
Velar analyzes cryptographic metadata: algorithms, key sizes, certificate chains, protocol versions and where they are used. We never request, store or transmit private key material.
How we protect it
- Encryption of customer data in transit (TLS) and at rest.
- Least-privilege access for staff, with access reviews and logging.
- Separation of customer data by organization.
- Deletion of customer data on request at the end of an engagement.
Certifications
Our SOC 2 Type II and ISO 27001 programs are in progress. We will publish attestation reports here once they are complete. Until then we are happy to complete security questionnaires and walk your team through our controls.
Reporting a vulnerability
If you believe you've found a security issue in Velar, please contact us. We ask that you give us reasonable time to investigate before any public disclosure.