Security & Trust¶
Vellocity handles GTM data for AWS ISV and consulting partners — listings, pipeline signals, agreements, and the cloud accounts you connect. This page summarizes how we protect it.
Data protection¶
- Encryption — data is encrypted in transit with TLS and at rest.
- Tenant isolation — each customer's data is logically isolated; one tenant cannot access another's data.
- Least-privilege access — production access is restricted to the people who need it and is audited.
Infrastructure¶
Vellocity runs entirely on AWS — the same cloud its customers sell on:
- Compute — Amazon EC2 behind an Application Load Balancer, TLS-terminated.
- Data — Amazon Aurora with encryption at rest and managed credential rotation; secrets live in AWS-managed secret stores, not in code or config files.
- AI — Amazon Bedrock, with guardrails applied to agent capabilities.
- Patching — hosts are rebuilt from patched golden AMIs on an automated pipeline rather than patched in place.
- Monitoring — Amazon CloudWatch metrics, canaries, and automated self-healing on the production fleet.
Cloud connections¶
When you connect a cloud account, Vellocity uses scoped, least-privilege credentials — never your root account. You grant only the permissions a capability needs, and you can revoke access at any time.
AI & your content¶
Vellocity grounds AI capabilities on the content you provide — your brand voice, knowledge base, listings, and uploads. Your data powers the features you run; it is not sold and is not used to train third-party foundation models. See AI Workflows for how content flows through capabilities.
Payments¶
Payments are processed by Stripe or transacted through AWS Marketplace (subscriptions and private offers). Vellocity never stores payment card numbers.
Privacy & terms¶
Reporting a vulnerability¶
Found a security issue? Email security@vell.ai with details and reproduction steps. We acknowledge reports and work with reporters in good faith to resolve them.