Security
How Velnor looks after your organisation's data, and how to tell us about a problem.
Each organisation apart
Every request runs as one organisation, and the database itself returns only that organisation's rows. A query that forgot to filter still couldn't read anyone else's data.
Accounts
Passwords are stored only as Argon2 hashes. Sign-in attempts are limited, and your session lives in a cookie scripts can't read, sent only to Velnor itself.
Encryption
Everything between you and Velnor travels over TLS, and browsers are told to use nothing else. The credentials you give Velnor to reach your channels are encrypted with a key per organisation.
AI
Most AI tasks run on models on our own servers. A task sent to a hosted provider carries only what it needs, and we never use your data to train models.
Backups and data region
Every database is backed up each day, with its changes archived as they happen, and backups are kept for 30 days. The region your data lives in is named here before launch.
This website
It sets no cookies and runs no third-party scripts, and its content policy lets the browser load only the site's own files.
Found a vulnerability?
Write to [email protected] with the subject “Security”, and how to reproduce it. We reply, keep you posted while we fix it, and credit you if you'd like.
Please test only your own account, don't reach other people's data or slow the service down, and give us the time to fix it before you publish. We won't take action against research done this way.