Trust & Security

Enterprise M&A intelligence, governed with evidence.

Velintis supports confidential transaction work through enterprise authentication, role-based authorization, deal-level access controls, auditability, and clear governance evidence for M&A intelligence workflows.

Platform trust is backed by implemented controls and reviewable evidence.

The Velintis platform includes enterprise authentication, RBAC, deal-level authorization, assigned analyst access, export protection, audit logging, access logging, and a Verification Report that evidences key controls.

Trust Principles

Designed for sensitive enterprise transaction work

01

Identity and Access

Enterprise authentication, role-based access control, and server-side authorization protect access to platform areas and deal information.

02

Deal-Scoped Security

Analysts work within an assigned-deal model, with deal data, documents, analysis, and report exports gated by deal-level authorization.

03

Evidence and Auditability

Security-relevant activity, access events, role changes, deal assignments, and report exports are recorded to support review and accountability.

Access Control

From authentication to deal-scoped authorization

Access is enforced through platform controls that separate administrative permissions, analyst assignments, deal information, and report exports.

01

Enterprise Authentication

Platform access requires an authenticated session through a managed identity provider. Velintis does not store user passwords.

02

Server-Side Authorization

Protected routes and actions invoke a shared authorization layer. Access decisions do not depend on the user interface.

03

Deal-Level Enforcement

Analyst access is constrained to assigned deals. Deal records, documents, analysis, exports, and administrative actions are protected by role and deal checks.

04

Logged Activity and Exports

Authentication events, access denials, role changes, deal assignments, analysis runs, and report exports are recorded in centralized logs.

Protection & Governance

Security controls and governed analysis

Implemented Controls

Controls protecting access, data, and exports

Enterprise authentication

Managed identity provider, authenticated sessions, and protected platform routes.

RBAC and deal authorization

Administrator and analyst roles are enforced server-side, with analysts limited to assigned deals.

Export protection

Report export endpoints are protected by the same authorization layer used across the platform.

Admin endpoint protection

Platform administration areas are restricted to authorized administrators and unauthorized attempts are recorded.

Audit and access logging

Security-relevant activity is recorded, including access events, authorization denials, role changes, and deal assignments.

Assigned analyst model

Deal assignments determine which analysts can access specific engagement records, documents, and outputs.

AI Governance

AI assists analysis; evidence supports decisions

Enabling capability

AI may assist document understanding, structured fact extraction, and drafting plain-language narratives.

Deterministic findings

Synergy and risk findings are generated through defined logic, with values derived from evidence and calculations.

Evidence and traceability

Each finding remains connected to the documents and extracted facts that support it.

Human review

Velintis analysts review findings before they inform a client deliverable.

Purpose limitation

Client documents are used to support the agreed engagement and are not used by Velintis to train general-purpose AI models.

Verification Evidence

Trust Center, Knowledge Base, and Verification Report

The internal Trust Center provides a transparent view of platform security, governance, privacy, operational controls, and verification evidence used to support customer due diligence.

Trust Center

Provides a structured view of platform security, governance, privacy, operational controls, and verification evidence.

Security Knowledge Base

Maintains the current descriptions of implemented controls and clearly identifies planned items.

Verification Report

Evidences authentication, authorization, RBAC, deal access, export protection, audit logging, and data retention controls.

Security Whitepaper

Consolidates Trust Center material into a technical reference for due-diligence and security review.

Subprocessors and Operations

Service providers and operational safeguards

Velintis uses selected service providers to support storage, hosting, authentication, data management, and AI-assisted analysis. Contractual terms and access controls apply according to their role.

Service providerPurpose
Amazon Web ServicesSecure file storage and supporting cloud services
AnthropicAI-supported document analysis
VercelApplication hosting
AivenManaged database services
ClerkAuthentication and session management

The DPA provides the contractual source of truth for subprocessor obligations and engagement-specific terms.

Incident response

Security-relevant activity and authorization denials support identification and investigation of security events.

Business continuity

Managed cloud services and source-controlled deployment support operational recovery planning.

Compliance

Velintis does not claim formal certifications; current controls and evidence are described through the Trust Center.

Trust Summary

Common questions about information handling

Security Contact

Questions about information handling?

Review the Privacy Policy and DPA, or contact the Velintis team to discuss engagement-specific requirements.