Trust & Evidence

Security & data posture

Isolated by tenant, in U.S. regions, with every action on the record.

Where your data lives

Velerian runs on AWS in U.S. regions — the same infrastructure major regulated institutions rely on. Your data is processed and stored in Velerian's cloud and kept isolated from every other customer's by enforced controls. Running Velerian entirely inside your own AWS account is on the roadmap (see below).

Scoped access, every action logged

The agent can only reach what it's explicitly granted, and every action it takes is recorded — so there's always a trail of what happened.

Residency, encryption, and scoped access

Velerian keeps your data in U.S. regions and encrypts it in transit and at rest under managed keys. Each customer gets tenant-scoped access, U.S. residency, and a clear record of who can reach what. Setting your own residency and encryption is available on the roadmap bring-your-own-AWS tier.

Security baseline from day one

Standard AWS protections — a web application firewall, threat detection (GuardDuty), and security monitoring (SecurityHub) — are switched on from the start, not added later.

On the roadmap

Bring-your-own-AWS — the option to run Velerian entirely inside your own AWS account — is planned.

Detailed security documentation — architecture, encryption, data residency, retention, and tenant isolation — is shared during a security review with prospective partners.