Security

Security, in plain language.

Velo keeps review access close to the release being discussed. Below are the boundaries you can rely on, and the limits of what this page establishes.

Security boundary diagramFive parties: a creator, a reviewer, the release between them, a capture worker and an evidence store. Solid lines are what each party may do. Dotted lines that trail off are paths that do not exist. Every node and line is listed in text after the drawing.edit, share, revoke1open by linkshare secret in the URL fragment,exchanged for a short-lived receipt2post, once verifiedrequests a capture,public HTTPS only3captured result,with release and device context4kept with the releaseproject settingsuser accountsrevoked linkCreatorproject editorReviewervia review linkReleasethreads and decisionsCapture workercapture jobs onlyEvidence storecaptured result

Parties

  • Creator, project editor
  • Reviewer, via review link
  • Release, threads and decisions
  • Capture worker, capture jobs only
  • Evidence store, captured result

Allowed, and authenticated

  • 1Creator to Release: edit, share, revoke
  • 2Reviewer to Release: open by link; the share secret in the URL fragment, exchanged for a short-lived receipt
  • Reviewer to Release: post to a thread, once verified
  • 3Creator to Capture worker: requests a capture of a public HTTPS target
  • 4Capture worker to Evidence store: writes the captured result, with release and device context
  • Evidence store to Release: kept with the release

Not reachable

  • Reviewer to project settings: no path
  • Capture worker to user accounts: no path
  • a revoked link to Release: no path
DiagramWho can reach the release, and what never can. The numbers point at the sections below.
  1. Access control stays scoped

    Project membership and external review grants are separate authority systems. For this phase, external review roles are viewer and commenter; a shared review does not grant project-editor access.

    Review link sharing makes two decisions independently: who can open a review and whether people with access may comment. The available link states are private and anyone with the link.

  2. Tokens have a narrow path

    Raw share secrets stay in URL fragments during handoff. Velo exchanges them for a short-lived HttpOnly receipt and stores token digests rather than reusable raw tokens.

    Share secrets are not placed in query strings, metadata, analytics, local storage, or operational logs. Expiry and revocation are part of the review-link boundary.

  3. Capture is bounded

    The capture proxy is capture-job-only. It accepts public HTTPS targets, re-checks redirects, blocks private, link-local, and metadata networks, and keeps egress bounded. It does not carry authenticated capture sessions.

    The installed overlay is for an exact verified HTTPS origin. It does not turn an arbitrary URL into a proxy session.

  4. Evidence and reporting

    Evidence limit: this page reflects architecture and policy documents. It does not establish production configuration, a retention period, an availability target, or an independent assessment.

Commitments

  • Retention windows are stated beside the data they govern, and removal follows the stated window.
  • Take a project export from the workspace at any time, or ask support to remove workspace data.
  • Membership changes, share-link changes, and publishing decisions are written to an audit trail with who decided and when.
  • Single sign-on arrives after the beta; until then, invites and the link states above describe who can open a review.
  • Data handling terms live in the privacy policy and the subprocessor registry; ask support for a data processing addendum.

No system is perfectly secure. If you suspect a vulnerability or unauthorized access, do not exploit or expose another person's data. Security research must be authorized in writing and limited to the approved scope.

Report a vulnerability to our legal contact. For the surrounding data and provider boundaries, read the privacy policy and subprocessor registry.