Ring 0 is open to design partners running agents against production systems. Request access

Security · trust centre

What we have, and what we do not.

Compliance pages usually imply more than they say. This one names the gaps, because you will find them in diligence anyway and it is cheaper for both of us if you find them now.

01 / certifications

FrameworkStatusDetail
SOC 2 Type IIcertifiedAnnual audit, Security and Availability. Report under NDA.
ISO 27001certifiedCertified ISMS covering the platform and corporate systems.
ISO 42001in progressAI management system. Audit scheduled for Q1 2027.
HIPAAcertifiedBAA available. Air-gapped or BYOC recommended for PHI.
GDPRcertifiedDPA with SCCs. EU-only residency available per session.
EU AI ActpartialCovers record-keeping and traceability duties for high-risk systems.
FedRAMPnot yetNot pursued yet. Air-gapped deployment is the current answer.
PCI DSSnot yetWe are not in scope; we never hold card data. Gateway keeps it out of the sandbox.

02 / control mapping

Where the product does the work for you.

These are the controls where using Velone materially reduces what you have to build and evidence yourself.

CC6.1 · logical access
Per-agent principals with no standing credentials, mapped to your identity provider. Access grants are per call and expire.
CC6.6 · boundary protection
Default-deny egress enforced at the gateway with pinned resolution, per session.
CC7.2 · monitoring
Complete, unsampled record of every agent action with decision and reason attached.
CC8.1 · change management
Policy is a version-controlled file; changes require human merge and appear in the evidence chain.
A.8.16 · monitoring activities
Session-level attribution and replay for anomaly investigation.
AI Act Art. 12 · record-keeping
Automatic, tamper-evident logging of system events over the lifetime of the deployment.
AI Act Art. 14 · human oversight
Escalation gates with named approvers and signed authorisations on irreversible actions.

03 / documents

SOC 2 Type II report
On request, under NDA.
ISO 27001 certificate
Available without NDA.
Penetration test summary
Latest external test, on request.
DPA with SCCs
Standard terms, signable as-is.
BAA
For HIPAA-covered deployments.
SBOM
Per release, on request or with air-gapped bundles.
Subprocessor list
Published and versioned.
Security questionnaire
Pre-filled CAIQ and SIG Lite.

04 / questions

You are early. Why should we trust your SOC 2?

A Type II report from a small company covers a real observation window but a narrow system. Read the scope section rather than the logo, and ask us about the exceptions — there were two in the last window and we will walk you through both.

Does using Velone make our agents compliant?

No. It closes the record-keeping, access control, and human-oversight gaps that most teams have no answer for. Your model choices, data handling, and intended use are still yours to assess.

Can we use Velone with regulated data?

Yes, and for PHI or material non-public information we will steer you to BYOC or air-gapped rather than managed. We would rather lose the easier deal than put you in the wrong deployment.

Who are your subprocessors?

The list is published and versioned, and we give 30 days' notice before adding one. In air-gapped deployments there are none.

keep reading

Ring 0

Ask for the report.

Send the questionnaire. We answer in days, not weeks, and we will tell you when the answer is no.

curl -fsSL velone.in/install.sh | sh