Security overview
This page states the controls implemented today and the gaps still being closed. It is not a certification. A more detailed security and privacy pack is available for qualified pilot reviews.
Deployment model
Velzio uses a standard desktop application on Windows and macOS, deployed through the device management tooling you already run. Builds are provided as part of onboarding, with instructions that match your environment.
Authentication
Admins currently use a Velzio account protected with time-based one-time passwords. The desktop authorization flow uses PKCE and DPoP. Microsoft Entra ID single sign-on and group targeting are planned capabilities, not current production claims.
Data minimization
Velzio stores admin account data, workspace settings, targeting identifiers and campaign completion data. It does not read or store the contents of employee files, email, chats or documents.
Customer isolation
Customer data is separated by tenant-scoped workspaces. Database row-level security reinforces tenant boundaries for rollout, targeting and completion data.
Audit-friendly history
Administrative events are recorded in an audit history with integrity checks. The detailed security pack explains the current scope and retention assumptions.
Backups
Production backup and recovery controls are not yet operational because the hosted production environment has not been provisioned. They must be verified before general availability.
Hosting
Microsoft Azure West Europe is the intended production region. The hosted production environment is not yet generally available. The sub-processor register will be finalized before customer production data is accepted.
Reporting a vulnerability
If you believe you have found a security issue, contact hello@velzio.io. Velzio does not operate a public bug bounty programme.