Skip to content

Security and trust

Security, built in.

How Velcio protects accounts, code and hosted applications across Cloud, Marketplace and Matz.

Clear boundaries, fewer assumptions.

Security controls follow the full path from account access to build, deployment and edge traffic.

Access and secrets

Platform and infrastructure access is limited to authorised Velcio staff. Deployment secrets are stored encrypted and protected by access controls.

Isolated workloads

Customer code is treated as untrusted and runs separately from the Velcio control plane with network and resource controls.

Replica health

Cloud checks each replica directly, so one failing instance is not hidden behind a healthy public application URL.

Protected traffic

Customer application ports are not exposed directly to the public internet. Traffic reaches workloads through Velcio's Cloudflare-protected edge, firewall and internal routing.

Across Velcio.

These practices apply across Cloud, Marketplace and Matz.

Cloud

Velcio Cloud

Builds, previews and hosted applications run through Velcio Cloud.

Marketplace

Velcio Marketplace

Previews and hosted handovers use Velcio Cloud.

AI builder

Matz

AI-assisted building uses models provided through Microsoft Azure. Previews and published apps use Velcio Cloud.

Where Velcio runs

The API and managed data services run on Microsoft Azure.

Velcio product frontends and customer applications run on Velcio Cloud infrastructure. Cloudflare routes and protects public application traffic.

Service providers and subprocessors

Providers used to operate Velcio and process data for the purposes shown below.

ProviderPurpose
Microsoft AzurePlatform infrastructure, managed data services and Matz model inference
Rica Web Services Inc.Contracted compute for Velcio Cloud workloads
Amazon Web Services (AWS)Contracted compute for Velcio Cloud workloads
CloudflareEdge routing, traffic protection and object storage
ClerkAuthentication and account management
StripePayments, subscriptions and Marketplace payouts
ResendTransactional email delivery
Google WorkspaceSupport inbox and customer correspondence
SentryError and performance monitoring
GitHubOptional source control integrations

Tell us when something is wrong.

Send a clear description, affected URL and reproduction steps. Please avoid accessing customer data beyond what is needed to demonstrate the issue.