Skip to content
Veldway

Company

Security

Last updated: 8 October 2026

Billing, payment, and business-critical systems are what we work on, so access to them is handled with care. These are the rules we work under. Each one is something you can check during an engagement.

Least-privilege access

We ask for the narrowest API scopes and roles that do the job — read-only wherever possible, staff roles instead of owner access, scoped tokens instead of master keys.

Your accounts, your credentials

Integrations run inside accounts you own. Secrets live in your platform settings and vaults — we don't keep parallel copies of your credentials.

Access ends at handover

Collaborator access is granted at the start and revoked at handover, with a written list of every system we touched so you can verify it yourself.

NDA and DPA, no friction

We'll sign your NDA before seeing anything sensitive, and a data-processing agreement where your data is in scope. GDPR-aware handling is the default, not an add-on.

Continuity by design

Runbooks, documentation, and full code ownership mean any competent developer can operate or take over what we build. The work never depends on us staying reachable.

Client data stays where it belongs

We work against staging environments and anonymised or test data wherever possible. When production data has to be examined, it is accessed in your systems rather than copied out of them, and any working copy that an engagement needs is deleted at handover.

Secrets are never shared in chat or email

Credentials are exchanged through your password manager, your platform's own invitation flow, or a one-time secret link — never pasted into email, chat, or tickets.

What we don't claim

We hold no security certifications such as SOC 2 or ISO 27001. We're happy to answer your vendor security questionnaire honestly, and to work within your own policies, VPN, or device requirements.

Reporting a vulnerability

If you find a security issue in this website or in anything we built, email hello@veldway.com with the details. We'll acknowledge it within one business day and keep you informed while it is fixed.

Commercial terms, including confidentiality, are on the engagement terms page; what this website collects is in the privacy policy.