How Veleiro is secured
Trust and security are built into every layer — from foundational models to your clients’ Salesforce orgs. The short version, in three commitments:
Your data stays yours
Zero-data-retention agreements with all LLM providers — no training, no retention beyond the API call. Credentials encrypted with AWS KMS envelope encryption, a unique data key per connection. Access mirrors your Salesforce user’s permissions — never escalates.
AWS-grade protection
Encrypted everywhere — at rest (KMS, SSE), in transit (TLS 1.3), in cache and queues. Real-time threat detection (GuardDuty + EventBridge), continuous vulnerability scanning (Inspector + Dependabot), aligned to the AWS CIS Foundations Benchmark. Private VPC, multi-AZ, least-privilege IAM.
AI that never acts alone
AI proposes, consultants deploy — every time. No direct AI writes to production Salesforce. Every agent action is logged and auditable, tagged to Partner, Organization, and User. Consultants review and approve all changes before deployment.
Tenant isolation, four layers deep
Every partner firm gets its own tenant, and isolation is enforced independently at four layers — a mistake at any one layer is caught by the others, and by CI:
A dedicated security test suite simulates cross-tenant access attempts through every public surface — APIs, files, AI search — and must pass before any change merges.
Want the full picture?
Our complete Security, Data & Platform Architecture document — foundational-model data flow, the Salesforce Connected App integration model, KMS envelope encryption, and the 2GP managed-package roadmap — is available to prospects and customers under NDA. Request it here.