Security
Security, in plain language.
Velo keeps review access close to the release being discussed. Below are the boundaries you can rely on, and the limits of what this page establishes.
Parties
- Creator, project editor
- Reviewer, via review link
- Release, threads and decisions
- Capture worker, capture jobs only
- Evidence store, captured result
Allowed, and authenticated
- 1Creator to Release: edit, share, revoke
- 2Reviewer to Release: open by link; the share secret in the URL fragment, exchanged for a short-lived receipt
- Reviewer to Release: post to a thread, once verified
- 3Creator to Capture worker: requests a capture of a public HTTPS target
- 4Capture worker to Evidence store: writes the captured result, with release and device context
- Evidence store to Release: kept with the release
Not reachable
- Reviewer to project settings: no path
- Capture worker to user accounts: no path
- a revoked link to Release: no path
Access control stays scoped
Project membership and external review grants are separate authority systems. For this phase, external review roles are viewer and commenter; a shared review does not grant project-editor access.
Review link sharing makes two decisions independently: who can open a review and whether people with access may comment. The available link states are private and anyone with the link.
Tokens have a narrow path
Raw share secrets stay in URL fragments during handoff. Velo exchanges them for a short-lived HttpOnly receipt and stores token digests rather than reusable raw tokens.
Share secrets are not placed in query strings, metadata, analytics, local storage, or operational logs. Expiry and revocation are part of the review-link boundary.
Capture is bounded
The capture proxy is capture-job-only. It accepts public HTTPS targets, re-checks redirects, blocks private, link-local, and metadata networks, and keeps egress bounded. It does not carry authenticated capture sessions.
The installed overlay is for an exact verified HTTPS origin. It does not turn an arbitrary URL into a proxy session.
Evidence and reporting
Evidence limit: this page reflects architecture and policy documents. It does not establish production configuration, a retention period, an availability target, or an independent assessment.
Commitments
- Retention windows are stated beside the data they govern, and removal follows the stated window.
- Take a project export from the workspace at any time, or ask support to remove workspace data.
- Membership changes, share-link changes, and publishing decisions are written to an audit trail with who decided and when.
- Single sign-on arrives after the beta; until then, invites and the link states above describe who can open a review.
- Data handling terms live in the privacy policy and the subprocessor registry; ask support for a data processing addendum.
No system is perfectly secure. If you suspect a vulnerability or unauthorized access, do not exploit or expose another person's data. Security research must be authorized in writing and limited to the approved scope.
Report a vulnerability to our legal contact. For the surrounding data and provider boundaries, read the privacy policy and subprocessor registry.