Our own posture
A compliance company without its own compliance is a punchline.
Here's exactly where we are. Updated as our own status changes — the same way your Trust Center will work.
- GDPR complianceActive
EU-incorporated, EU data residency, DPA on request.
- SOC 2 Type IIn progress — report Q3
Auditor engaged, observation period started.
- SOC 2 Type IIIn observation
- ISO 27001Planned 2027
Once SOC 2 is shipped.
- Encryption at restAES-256 (Supabase managed keys)
- Encryption in transitTLS 1.3 only
- Data residencyEU (Frankfurt)
- MFA enforcementRequired for all Veylan staff
- Penetration testingAnnual (next: Q4 2026)
- Backup + DRHourly backups, RPO 1h, RTO 4h
Want the long version? Email security@veylan.com for our security questionnaire response or a copy of the SOC 2 report when it's available.