Company
Security
Last updated: 8 October 2026
Billing, payment, and business-critical systems are what we work on, so access to them is handled with care. These are the rules we work under. Each one is something you can check during an engagement.
Least-privilege access
We ask for the narrowest API scopes and roles that do the job — read-only wherever possible, staff roles instead of owner access, scoped tokens instead of master keys.
Your accounts, your credentials
Integrations run inside accounts you own. Secrets live in your platform settings and vaults — we don't keep parallel copies of your credentials.
Access ends at handover
Collaborator access is granted at the start and revoked at handover, with a written list of every system we touched so you can verify it yourself.
NDA and DPA, no friction
We'll sign your NDA before seeing anything sensitive, and a data-processing agreement where your data is in scope. GDPR-aware handling is the default, not an add-on.
Continuity by design
Runbooks, documentation, and full code ownership mean any competent developer can operate or take over what we build. The work never depends on us staying reachable.
Client data stays where it belongs
We work against staging environments and anonymised or test data wherever possible. When production data has to be examined, it is accessed in your systems rather than copied out of them, and any working copy that an engagement needs is deleted at handover.
Secrets are never shared in chat or email
Credentials are exchanged through your password manager, your platform's own invitation flow, or a one-time secret link — never pasted into email, chat, or tickets.
What we don't claim
We hold no security certifications such as SOC 2 or ISO 27001. We're happy to answer your vendor security questionnaire honestly, and to work within your own policies, VPN, or device requirements.
Reporting a vulnerability
If you find a security issue in this website or in anything we built, email hello@veldway.com with the details. We'll acknowledge it within one business day and keep you informed while it is fixed.
Commercial terms, including confidentiality, are on the engagement terms page; what this website collects is in the privacy policy.