Security · trust centre
What we have, and what we do not.
Compliance pages usually imply more than they say. This one names the gaps, because you will find them in diligence anyway and it is cheaper for both of us if you find them now.
01 / certifications
| Framework | Status | Detail |
|---|---|---|
| SOC 2 Type II | certified | Annual audit, Security and Availability. Report under NDA. |
| ISO 27001 | certified | Certified ISMS covering the platform and corporate systems. |
| ISO 42001 | in progress | AI management system. Audit scheduled for Q1 2027. |
| HIPAA | certified | BAA available. Air-gapped or BYOC recommended for PHI. |
| GDPR | certified | DPA with SCCs. EU-only residency available per session. |
| EU AI Act | partial | Covers record-keeping and traceability duties for high-risk systems. |
| FedRAMP | not yet | Not pursued yet. Air-gapped deployment is the current answer. |
| PCI DSS | not yet | We are not in scope; we never hold card data. Gateway keeps it out of the sandbox. |
02 / control mapping
Where the product does the work for you.
These are the controls where using Velone materially reduces what you have to build and evidence yourself.
- CC6.1 · logical access
- Per-agent principals with no standing credentials, mapped to your identity provider. Access grants are per call and expire.
- CC6.6 · boundary protection
- Default-deny egress enforced at the gateway with pinned resolution, per session.
- CC7.2 · monitoring
- Complete, unsampled record of every agent action with decision and reason attached.
- CC8.1 · change management
- Policy is a version-controlled file; changes require human merge and appear in the evidence chain.
- A.8.16 · monitoring activities
- Session-level attribution and replay for anomaly investigation.
- AI Act Art. 12 · record-keeping
- Automatic, tamper-evident logging of system events over the lifetime of the deployment.
- AI Act Art. 14 · human oversight
- Escalation gates with named approvers and signed authorisations on irreversible actions.
03 / documents
- SOC 2 Type II report
- On request, under NDA.
- ISO 27001 certificate
- Available without NDA.
- Penetration test summary
- Latest external test, on request.
- DPA with SCCs
- Standard terms, signable as-is.
- BAA
- For HIPAA-covered deployments.
- SBOM
- Per release, on request or with air-gapped bundles.
- Subprocessor list
- Published and versioned.
- Security questionnaire
- Pre-filled CAIQ and SIG Lite.
04 / questions
You are early. Why should we trust your SOC 2?
A Type II report from a small company covers a real observation window but a narrow system. Read the scope section rather than the logo, and ask us about the exceptions — there were two in the last window and we will walk you through both.
Does using Velone make our agents compliant?
No. It closes the record-keeping, access control, and human-oversight gaps that most teams have no answer for. Your model choices, data handling, and intended use are still yours to assess.
Can we use Velone with regulated data?
Yes, and for PHI or material non-public information we will steer you to BYOC or air-gapped rather than managed. We would rather lose the easier deal than put you in the wrong deployment.
Who are your subprocessors?
The list is published and versioned, and we give 30 days' notice before adding one. In air-gapped deployments there are none.
keep reading
Ring 0
Ask for the report.
Send the questionnaire. We answer in days, not weeks, and we will tell you when the answer is no.