SECURITY MANIFESTO

Your mind is not
the product.

Veln is a passive cognitive mirror.
We treat data as a liability, not an asset.

We minimize data by design — storing only what is required for the reflection cycle.

01. INFRASTRUCTURE

Technical Safeguards

Storage (At Rest)

Standard: AES-256-GCM
Engine: Neon Postgres / AWS KMS
Location: AWS Region us-east-1

Data is siloed at the hardware level. The physical storage volumes are encrypted with unique keys managed by AWS Key Management Service.

Transit (In Motion)

Protocol: TLS 1.3 / HSTS
Certificate: Let's Encrypt / Vercel Edge
Encryption: 2048-bit RSA

Every fragment is encrypted via TLS 1.3 before leaving your device. We enforce HSTS to prevent downgrade attacks.

02. GOVERNANCE

Data Sovereignty

Hard Purge

The Right to Disappear

Account deletion triggers an immediate database-level cascade. We do not keep shadow archives, cold backups, or logs of your personal reflections once deleted.

Portability

The Right to Carry

Export your entire history at any time as a raw, structured JSON file. Your data is your property; our interface is simply a lens.

03. INTELLIGENCE

AI Processing Policy

No Training

Your data is never used to train, fine-tune, or improve public foundation models.

Zero Identity

We do not pass PII (Names, Emails) to AI sub-processors. Only raw thought fragments are analyzed.

Transient Processing

AI processing occurs in a stateless context. Content is not retained by the AI provider after summary generation.