Security

Report a security issue

Found something? We want to hear about it — fast, directly, and without friction. Security researchers acting in good faith are welcome here.

Write to us directlysecurity@veleiro.aiWe acknowledge every report within 2 business days.
Report an issue

How Veleiro is secured

Trust and security are built into every layer — from foundational models to your clients’ Salesforce orgs. The short version, in three commitments:

Your data stays yours

Zero-data-retention agreements with all LLM providers — no training, no retention beyond the API call. Credentials encrypted with AWS KMS envelope encryption, a unique data key per connection. Access mirrors your Salesforce user’s permissions — never escalates.

AWS-grade protection

Encrypted everywhere — at rest (KMS, SSE), in transit (TLS 1.3), in cache and queues. Real-time threat detection (GuardDuty + EventBridge), continuous vulnerability scanning (Inspector + Dependabot), aligned to the AWS CIS Foundations Benchmark. Private VPC, multi-AZ, least-privilege IAM.

AI that never acts alone

AI proposes, consultants deploy — every time. No direct AI writes to production Salesforce. Every agent action is logged and auditable, tagged to Partner, Organization, and User. Consultants review and approve all changes before deployment.

Tenant isolation, four layers deep

Every partner firm gets its own tenant, and isolation is enforced independently at four layers — a mistake at any one layer is caught by the others, and by CI:

1 · DataEvery record is bound to its tenant at creation — records cannot be moved between tenants.
2 · QueryEvery database read is forced to filter by tenant before any data is returned.
3 · RequestEvery API request is bound to the authenticated user’s tenant before any business logic runs.
4 · StorageFiles and AI knowledge bases are partitioned per tenant — never pooled into a shared index.

A dedicated security test suite simulates cross-tenant access attempts through every public surface — APIs, files, AI search — and must pass before any change merges.

Want the full picture?

Our complete Security, Data & Platform Architecture document — foundational-model data flow, the Salesforce Connected App integration model, KMS envelope encryption, and the 2GP managed-package roadmap — is available to prospects and customers under NDA. Request it here.

Security review coming up?

Bring your questionnaire — we’ll walk your security team through every layer.

Talk to us