Trust center
A practical summary of what Veil protects, what the cloud processes, who supports the service and where the product’s limits remain.
Last reviewed: 14 July 2026 · Applies to Veil 1.5
Detection, masking, encryption and decryption run in the browser. Veil uses AES-GCM with PBKDF2-derived keys for local protected text.
Personal and Business passphrases are retained locally and are not uploaded, synchronized or recoverable by Goldspire.
Every Personal or Business browser using cloud features requires mailbox approval. Business administrators can revoke browsers individually.
| Provider | Purpose | Typical data |
|---|---|---|
| Cloudflare | Portal delivery, DNS, TLS and edge security | IP address and request metadata |
| Railway | API hosting and application runtime | Account, organization, policy, support and event metadata processed by the API |
| Supabase | Managed PostgreSQL database | Accounts, approvals, policies, ciphertext, billing references and security metadata |
| Stripe | Subscription checkout and billing | Customer, subscription and payment information; Goldspire does not store full card details |
| Brevo / Resend | Transactional email | Recipient email, verification or invitation content and delivery metadata |
| GitHub | Private source control and release automation | Source code, CI logs and development metadata; production customer content is not intentionally stored there |
Customer-configured SIEM or identity destinations are controlled by the customer and are not Goldspire subprocessors for that independent use.
| Data class | Default retention |
|---|---|
| Browser approval tokens | 24 hours or successful approval |
| Revoked or expired join codes | 90 days |
| Revoked browser records | 12 months, unless needed for a security investigation |
| Security-event metadata | 90 days by default |
| Encrypted token/share blobs | Configured expiry or read limit; maximum 90 days unless contractually extended |
| Support tickets | 24 months after closure |
| Operational request metrics | 30 days |
| Database backups | 35 days |
| Billing records | Contract term plus statutory accounting/tax period where required |
Database migrations, automated tests, loaded-extension smoke tests, route checks, mobile/desktop screenshots and release safety checks run before packaging.
Goldspire maintains incident classification, containment, evidence, notification and recovery procedures for Veil operations.
Production readiness includes managed backups, restore procedures and recorded recovery exercises.
Veil includes policy context for GDPR, PCI DSS, HIPAA, SOC 2 and ISO 27001-aligned workflows. These mappings are product guidance; they do not make a customer compliant and do not represent certification of Goldspire or Veil.
Enterprise customers may request the available security and procurement materials from Sales.
Send security reports privately. Include the affected feature, reproduction steps and potential impact. Do not access other users’ data or run disruptive testing.