Velaris Security Portal

Overview

Welcome to Velaris' Security Portal. Our commitment to data privacy and security is embedded in every part of our business. Use this portal to learn about our security posture and request access to our security documentation.

Compliance
Iso certificationGDPR certification badge
Risk profile icon

Risk Profile

Data Access Level

As a SaaS vendor selling to an enterprise test
, what type of data do you need access to?

Restricted (i.e. highly confidential information such as PII, personal identifiable information)

Impact Level

What is the potential impact to your enterprise customer if the data and/or functionality you, as the vendor, are supposed to manage, is compromised?

Substantial

Recovery Time Objective

What is your recovery time objective in case of critical failure? (e.g., your DB is deleted)

24 – 48 hours

Recovery Point Objective

What is your recovery point objective in case of critical failure? (e.g., your DB is deleted)

24 – 48 hours

Critical Dependence

Will your product be a system that your enterprise customer critically depends on? (i.e., a failure would cost them a ton of money)

No

Third Party Dependence

Are you also using other third-party services to manage or support your customers?

Yes

Hosting

Are you hosted only on one of the major cloud providers or do you have any on-premise systems?

Major Cloud Provider (e.g., AWS)

reports icon

Reports

Pentest Report

Auditor

7ASecurity

We engaged 7ASecurity to perform a thorough white-box penetration test of the Velaris. All identified issues were fixed by Velaris and verified by the 7ASecurity team.

data icon

Data Security

Backups Enabled

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Data Erasure

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Encryption-at-rest

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Encryption-in-transit

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Physical Security

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

app icon

App Security

Credential Management

We manage all secrets using the Doppler SecretOps Platform.

Responsible Disclosure

We appreciate your help in reporting bugs and have set up a bug bounty program to reward your efforts. Please reach out to support@velaris.io to report a bug.

Vulnerability & Patch Management

We install all patches and software updates as soon as they are made available. All vulnerabilities are tracked in our project management system.

legal icon

Legal

Subprocessors

Company

Location

Additional details

AWS logo

Amazon Web Services

USA

Cloud infrastructure

Data Processing Agreement
Master Services Agreement
access icon

Access Control

Data Access

We strictly monitor access to customer data and only permit it on an as-needed basis.

Logging

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Password Security

We enforce stringent password security policies and MFA-based access for all our employees via a central Identity Provider.

infrastructure icon

Infrastructure

Amazon Web Services

We host our applications and data on Amazon Web Services

Separate Production Environment

We maintain completely separate production and development environments to ensure product stability.

corporate security icon

Corporate Security

Asset Management Practices

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Employee Training

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

HR Security

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Internal SSO

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

policies icon

Policies

Acceptable Use Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Access Control Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Asset Management Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Backup Policy

We maintain a Backup Policy as part of our Operations Security Policy under "Information Backup."Request Access

Business Continuity Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

BYOD Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Data Classification Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Encryption Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Information Security Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Internal and External Communication Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Password Policy

Our password policy is incorporated into our Acceptable Use Policy under "Acceptable and Unacceptable Use of User Accounts and Passwords."

Physical Security

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Risk Management Policy

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.

Software Development Lifecycle

Lorem ipsum dolor sit amet. Est quam ratione aut sunt rerum ut amet molestiae qui illo nulla At eveniet quaerat.