Security and
data handling.

How the hosted service protects customer documents, manages access and preserves project records.

Protecting customer information.

Vellint uses Amazon Web Services for hosted infrastructure. The controls below describe how the service handles customer information. For questions about a security assessment or your organisation’s requirements, contact us.

contact@vellint.com
01

Access and authorization

Users sign in with an individual account. Access depends on their organisation, role and assigned projects. The service checks these permissions when a request is made, so signing in does not give a user access to every project.

02

Organisation and project access

Customer records and files are associated with the organisation that owns them. Database and storage access controls enforce these boundaries. Project permissions determine which members can view or work on a project.

03

Data handling

Source documents, templates, engineering inputs and drafts are held in private storage. They are not published on the website. Customers retain ownership of their content; Vellint processes it to provide, support and secure the service.

04

Encryption

The website and hosted application use HTTPS to protect data in transit. Hosted project files, databases and persistent working storage are encrypted at rest. Service credentials are held separately from application source code.

05

AI processing

AI-assisted operations send relevant project material to an external model provider. This can include source text, engineering inputs and draft content. Users review the catalogue, resolve engineering questions and confirm document revisions. AI-generated content requires professional review before it is relied on or issued.

06

Traceability and provenance

The workflow records source references, engineering inputs, decisions and document revisions. This helps reviewers distinguish source requirements from assumptions and human decisions. Confirmed revisions are saved as read-only records.

07

Operational monitoring

The hosted service records job progress, operational events and administrative activity to support fault diagnosis and security reviews. Administrative telemetry excludes controlled project content by default.

08

Retention and deletion

Active project records and saved revisions are retained to support ongoing work and review history. Unused uploads and temporary working files are subject to cleanup. Archiving a project or organisation does not delete its records. Contact us to arrange data deletion, subject to the customer agreement, backups and legal requirements.

Responsible disclosure

To report a suspected security issue or discuss a customer security review, email contact@vellint.com. Please avoid including sensitive project data in the first message.