Security that ships in the product, not just on this page

Velsano holds your customer relationships — health, revenue, conversations. That data deserves specifics, not adjectives. This page lists what the product actually does to protect it, how AI access is governed, exactly which vendors process data on our behalf, and how to reach us about a vulnerability.

Authentication & identity

Tenant isolation & access control

Encryption & data protection

Auditability & change management

AI governance

Data lifecycle

Subprocessors — who touches your data, and why

Velsano runs on a small, named set of infrastructure and service providers. This is the complete list of vendors that process data as part of operating the platform:

VendorPurposeWhat it processes
VercelFrontend hosting (marketing site and app shell)Web traffic
RailwayAPI hostingApplication traffic in transit
NeonManaged PostgreSQL (primary database)Workspace data at rest, storage-encrypted
Cloudflare R2File attachments and encrypted backupsUploaded files; encrypted backup archives
AnthropicAll LLM features, via a single governed gatewayThe specific account context a feature needs, governed by your AI controls
OpenAIText embeddings for semantic search — off by default, per-workspace opt-inText selected for embedding, only if enabled
ResendTransactional and program email deliveryRecipient addresses and email content
StripeSubscription billingBilling contact and subscription details — card data never touches Velsano
SentryError monitoring (optional)Error traces with secrets scrubbed

Integrations you enable are different

Connectors — Salesforce, HubSpot, Google, Zendesk, Jira, Slack, Zoom, SAP BDC, Databricks, Snowflake, S3/SFTP and others — exchange data only for your workspace, only after one of your admins connects them, with credentials encrypted at rest. They are opt-in integrations under your control, not always-on subprocessors.

Responsible disclosure

Found a vulnerability? We want to hear about it. Email us with enough detail to reproduce the issue; we will acknowledge quickly, keep you informed while we fix it, and credit you for the find if you would like. Contact: support@velsano.ai

Frequently asked questions

Is my data isolated from other customers?
Yes. Every query runs behind a tenant boundary applied automatically at the data-access layer, and an automated cross-tenant probe suite verifies that isolation. A database-level row-security policy is additionally proven by automated test as defense-in-depth, with production isolation enforced at the application layer today.
What does the AI see, and can we control it?
Only what you allow. Admins can deny specific AI tools and data objects per workspace, and the denylist applies to every AI surface including the MCP server. Agents propose actions for human approval, untrusted content is fenced before it reaches a model, and all LLM traffic flows through one governed, metered gateway.
Can we delete our data?
Yes. Retention policies anonymize raw free-text past your configured threshold automatically, and workspace admins can trigger complete erasure with an explicit confirmation step — the purge is derived from the data model so nothing is left behind. Accidental in-app deletions are recoverable from the Trash first.
Where does my data live?
Primary data lives in managed PostgreSQL (Neon) with storage-level encryption; attachments and encrypted nightly backups live in Cloudflare R2. The subprocessor table above is the complete list of vendors that process data on our behalf.

Start your free 14-day trial · Talk to us