Applied VelocityBack to site

Trust / Security

Security

How Applied Velocity protects organisational evidence and where our assurance programme stands today.

Last updated 15 August 2026
01

Our security approach

Applied Velocity is designed to handle sensitive organisational evidence. We use technical and organisational safeguards intended to protect confidentiality, integrity and availability throughout the service lifecycle.

Security is risk-based and continuously improved. This overview describes the current programme at a high level; customer-specific commitments are set out in the applicable agreement and security schedule.

02

Platform and infrastructure

  • Application traffic is served over encrypted HTTPS connections.
  • The platform runs on Cloudflare infrastructure and uses managed storage services for application data and files.
  • Environment secrets and production bindings are separated from application code.
  • Rate limiting and Cloudflare Turnstile are used on relevant public and account-access flows to reduce automated abuse.
  • Operational errors are logged with sensitive-value redaction controls.
03

Identity and access

  • Signed-in sessions use secure, host-scoped cookies on production deployments.
  • Workspace access is scoped to authorised users and organisations.
  • Administrative access uses separate session handling and can be revoked.
  • API credentials can be created and revoked by authorised users.
  • Passwords are processed using one-way password hashing.
04

Data and AI processing

Workspace data can include organisation structures, interviews, transcripts, files, messages and reports. Access is limited through application permissions and customer workspace membership.

AI features use model providers, including OpenAI, routed through Cloudflare AI Gateway where configured. We work to minimise unnecessary data sent to providers and document provider use in customer agreements or supporting material. Customers should not submit data outside the agreed scope.

See the privacy policy for more information about processing, providers, retention and individual rights.

05

Secure development and operations

  • Changes are reviewed and verified through automated tests and build checks.
  • Dependencies and platform configuration are maintained as the product evolves.
  • Production secrets are never committed to source control.
  • Backups, recovery and operational procedures are reviewed according to service risk.
  • Security events are investigated and remediated according to severity.
06

SOC 2 readiness status

SOC 2 readinessIn progress

Applied Velocity is building its control, policy and evidence programme toward a future SOC 2 examination. This work is in progress. Applied Velocity has not completed a SOC 2 examination, received a SOC 2 report, or been certified. The status badge communicates programme progress only and is not an AICPA mark.

07

Reporting a security concern

If you believe you have found a vulnerability or security incident, email contact@appliedvelocity.ai with “Security report” in the subject line. Include enough detail to reproduce the issue without accessing, altering or sharing data that is not yours.

Do not perform denial-of-service testing, social engineering, destructive testing or automated scanning that could affect customers. We will acknowledge good-faith reports and coordinate remediation and disclosure where appropriate.

08

Customer responsibilities

Security is shared. Customers should manage membership promptly, use strong unique credentials, protect API and MCP secrets, configure integrations carefully, restrict sensitive data to the agreed scope, review permissions regularly, and tell us immediately about suspected compromise.