🛡️Security at Velantx LLC
At Velantix LLC, security is foundational to how the Axiom platform is designed, operated, and continuously improved.
Axiom is built to support enterprise infrastructure analysis and modernization initiatives where operational trust, data protection, and controlled access are critical.
📉Data Minimization
Velantix Axiom™ assessments are designed to work from infrastructure metadata exports such as RVTools. Standard assessments do not require production credentials, direct system access, or access to customer workloads.
📥Controlled Intake
Customer files are handled through a guided intake process and used only for the requested assessment.
👥Limited Access
Assessment files are reviewed only by authorized Velantix LLC personnel involved in producing the deliverable.
🗓️Retention
Customer-provided assessment data may be deleted upon request after delivery, unless retention is required for an active engagement or agreed follow-on work.
🤝NDA Available
Mutual NDAs are available before file submission when required by the customer.
🔐Security Principles
Velantix LLC follows several core security principles:
- Least privilege access
- Segmented infrastructure design
- Encrypted communications
- Controlled administrative access
- Continuous monitoring and logging
- Secure development practices
🗄️Data Protection
Axiom is designed to analyze infrastructure and operational metadata rather than customer business content whenever possible.
Security protections may include:
- TLS-encrypted communications
- Encrypted storage services
- Access auditing
- Role-based permissions
- Environment isolation controls
🌐Network Security Policy
Velantix Axiom's network architecture is designed so that internal processing systems are never directly reachable from the public internet.
- Public traffic terminates at a managed, global edge network before reaching any internal system
- Assessment processing infrastructure runs in a private, isolated network with no public IP address and no open inbound ports
- Administrative access to processing infrastructure is performed through short-lived, authenticated, and logged connections rather than direct network access
- Network boundaries are isolated per engagement, limiting the scope of any single environment
- All traffic in transit is encrypted using TLS
🔒Encryption Policy
Encryption is applied across the full lifecycle of assessment data — in transit, at rest, and during processing.
- All data in transit is encrypted using TLS, including portal sessions, file uploads, and internal service-to-service communication
- Customer inventory data, generated deliverables, and audit records are stored using encrypted storage services
- Encryption keys are managed through a dedicated key management service, with regional key isolation available for engagements with data residency requirements
- Application secrets and credentials are stored in a managed secrets service and retrieved at runtime — never embedded in source code or machine images
- Encryption configuration is applied consistently through infrastructure-as-code rather than manual setup, so protections cannot be silently disabled or drift over time
👤Access Controls
Administrative and operational access to platform systems is restricted to authorized personnel based on operational responsibilities.
Authentication and access management practices are designed to minimize unauthorized access risk.
🖥️Endpoint & Physical Security
Administrative access to the platform is protected at the device, credential, and facility level, not just at the network boundary.
- Administrative devices run continuous endpoint protection, including antimalware, antiphishing, and advanced threat detection, with automated compliance and security audit reporting on a regular schedule
- Administrative and cloud provider credentials are managed through a dedicated password manager with unique, high-strength passwords and continuous compromise monitoring
- Administrative network access operates behind a dedicated firewall with no open inbound ports
- The facility housing administrative equipment is protected by monitored surveillance and access-logged entry controls
🤖AI and Data Handling
AI-assisted analysis capabilities are designed to operate on infrastructure telemetry, configuration metadata, and assessment-related operational data. Every Axiom assessment combines AI-assisted analysis with expert architectural validation.
Velantix LLC does not intentionally use uploaded customer assessment data for public AI model training.
🧪Secure Development Practices
Velantix LLC incorporates security considerations into platform architecture, code review processes, change management, dependency management, and infrastructure deployment workflows.
🚨Responsible Disclosure
If you believe you have identified a security issue or vulnerability, please contact:
[email protected]
Please include:
- Description of the issue
- Steps to reproduce
- Relevant screenshots or logs if applicable
Velantix LLC appreciates responsible disclosure practices and will investigate reported concerns promptly.
🧭Future Compliance Roadmap
Velantix LLC is designing operational and platform processes with future enterprise and regulated-environment readiness in mind, including alignment toward security best practices, enterprise governance expectations, and government and regulated industry requirements.