Access and secrets
Platform and infrastructure access is limited to authorised Velcio staff. Deployment secrets are stored encrypted and protected by access controls.
Security and trust
How Velcio protects accounts, code and hosted applications across Cloud, Marketplace and Matz.
Security controls follow the full path from account access to build, deployment and edge traffic.
Platform and infrastructure access is limited to authorised Velcio staff. Deployment secrets are stored encrypted and protected by access controls.
Customer code is treated as untrusted and runs separately from the Velcio control plane with network and resource controls.
Cloud checks each replica directly, so one failing instance is not hidden behind a healthy public application URL.
Customer application ports are not exposed directly to the public internet. Traffic reaches workloads through Velcio's Cloudflare-protected edge, firewall and internal routing.
These practices apply across Cloud, Marketplace and Matz.
Builds, previews and hosted applications run through Velcio Cloud.
Previews and hosted handovers use Velcio Cloud.
AI-assisted building uses models provided through Microsoft Azure. Previews and published apps use Velcio Cloud.
The API and managed data services run on Microsoft Azure.
Velcio product frontends and customer applications run on Velcio Cloud infrastructure. Cloudflare routes and protects public application traffic.
Providers used to operate Velcio and process data for the purposes shown below.
| Provider | Purpose |
|---|---|
| Microsoft Azure | Platform infrastructure, managed data services and Matz model inference |
| Rica Web Services Inc. | Contracted compute for Velcio Cloud workloads |
| Amazon Web Services (AWS) | Contracted compute for Velcio Cloud workloads |
| Cloudflare | Edge routing, traffic protection and object storage |
| Clerk | Authentication and account management |
| Stripe | Payments, subscriptions and Marketplace payouts |
| Resend | Transactional email delivery |
| Google Workspace | Support inbox and customer correspondence |
| Sentry | Error and performance monitoring |
| GitHub | Optional source control integrations |
Send a clear description, affected URL and reproduction steps. Please avoid accessing customer data beyond what is needed to demonstrate the issue.