Trust center

Security boundaries you can evaluate

A practical summary of what Veil protects, what the cloud processes, who supports the service and where the product’s limits remain.

Last reviewed: 14 July 2026 · Applies to Veil 1.5

Core security model

Local protection

Detection, masking, encryption and decryption run in the browser. Veil uses AES-GCM with PBKDF2-derived keys for local protected text.

Customer-held passphrases

Personal and Business passphrases are retained locally and are not uploaded, synchronized or recoverable by Goldspire.

Verified browsers

Every Personal or Business browser using cloud features requires mailbox approval. Business administrators can revoke browsers individually.

Cloud data boundaries

Service providers

ProviderPurposeTypical data
CloudflarePortal delivery, DNS, TLS and edge securityIP address and request metadata
RailwayAPI hosting and application runtimeAccount, organization, policy, support and event metadata processed by the API
SupabaseManaged PostgreSQL databaseAccounts, approvals, policies, ciphertext, billing references and security metadata
StripeSubscription checkout and billingCustomer, subscription and payment information; Goldspire does not store full card details
Brevo / ResendTransactional emailRecipient email, verification or invitation content and delivery metadata
GitHubPrivate source control and release automationSource code, CI logs and development metadata; production customer content is not intentionally stored there

Customer-configured SIEM or identity destinations are controlled by the customer and are not Goldspire subprocessors for that independent use.

Default retention

Data classDefault retention
Browser approval tokens24 hours or successful approval
Revoked or expired join codes90 days
Revoked browser records12 months, unless needed for a security investigation
Security-event metadata90 days by default
Encrypted token/share blobsConfigured expiry or read limit; maximum 90 days unless contractually extended
Support tickets24 months after closure
Operational request metrics30 days
Database backups35 days
Billing recordsContract term plus statutory accounting/tax period where required

Operational security

Release controls

Database migrations, automated tests, loaded-extension smoke tests, route checks, mobile/desktop screenshots and release safety checks run before packaging.

Incident response

Goldspire maintains incident classification, containment, evidence, notification and recovery procedures for Veil operations.

Backup and recovery

Production readiness includes managed backups, restore procedures and recorded recovery exercises.

Compliance posture

Veil includes policy context for GDPR, PCI DSS, HIPAA, SOC 2 and ISO 27001-aligned workflows. These mappings are product guidance; they do not make a customer compliant and do not represent certification of Goldspire or Veil.

Enterprise customers may request the available security and procurement materials from Sales.

Report a vulnerability

Send security reports privately. Include the affected feature, reproduction steps and potential impact. Do not access other users’ data or run disruptive testing.