Home

Security & Trust

How Veltro protects your account, your website data, and any Google data you choose to connect.

Encryption in transit and at rest
All traffic uses HTTPS/TLS. Sensitive fields and OAuth tokens are encrypted at rest.
Authentication & MFA
Passwords are hashed; app-based two-factor authentication (TOTP) is available, with one-time backup codes. Changing your password requires your current password.
Google data (Search Console / GA4)
Connection is optional and requested in context. We ask only for the scopes needed, show them before you connect, store tokens encrypted, and let you revoke access at any time. Disconnecting removes imported data.
Data isolation
Every record is partitioned per account. Your data is never mixed with another customer's.
Access controls & logging
Sensitive account changes are logged. Administrative access is restricted and audited.
Rate limiting & abuse protection
Login, password-reset and 2FA endpoints are rate-limited to slow brute-force attempts.
Backups & recovery
The database is backed up regularly; recovery procedures are tested.
Data deletion
You can request deletion of your account and data from your account page or by emailing privacy@veltro.cash. Backups are purged on our retention cycle.
Responsible disclosure
Found a vulnerability? Email security@veltro.cash. We investigate every report and will acknowledge yours.
Subprocessors & data residency
We use vetted providers for hosting, payments and email. A current list of subprocessors and storage regions is available on request and will be published here.

Security questions or reports: security@veltro.cash