Legal

Security

How we protect our platform — and how to report a vulnerability.

Our approach

Velizor builds and operates its platform to the same standards we help customers achieve. Security is embedded across our engineering, infrastructure, and operations.

Practices

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Least-privilege access, SSO, and audit logging
  • Secure software development lifecycle with code review
  • Continuous monitoring, logging, and incident response
  • Regular third-party penetration testing

Compliance

For our certifications and compliance posture, see the Trust Center.

Responsible disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability, please email admin@velizor.ai with details and steps to reproduce. We commit to acknowledging reports promptly and will not pursue legal action for good-faith research conducted under this policy.

Please do not publicly disclose an issue until we've had a reasonable opportunity to investigate and remediate.