Trust Center

Security and Data Handling

Security principles, controlled intake practices, and platform protection safeguards for Velantix Axiom™ assessments.

Last Updated · August 4, 2026

🛡️Security at Velantx LLC

At Velantix LLC, security is foundational to how the Axiom platform is designed, operated, and continuously improved.

Axiom is built to support enterprise infrastructure analysis and modernization initiatives where operational trust, data protection, and controlled access are critical.

📉Data Minimization

Velantix Axiom™ assessments are designed to work from infrastructure metadata exports such as RVTools. Standard assessments do not require production credentials, direct system access, or access to customer workloads.

📥Controlled Intake

Customer files are handled through a guided intake process and used only for the requested assessment.

👥Limited Access

Assessment files are reviewed only by authorized Velantix LLC personnel involved in producing the deliverable.

🗓️Retention

Customer-provided assessment data may be deleted upon request after delivery, unless retention is required for an active engagement or agreed follow-on work.

🤝NDA Available

Mutual NDAs are available before file submission when required by the customer.

🔐Security Principles

Velantix LLC follows several core security principles:

  • Least privilege access
  • Segmented infrastructure design
  • Encrypted communications
  • Controlled administrative access
  • Continuous monitoring and logging
  • Secure development practices

🗄️Data Protection

Axiom is designed to analyze infrastructure and operational metadata rather than customer business content whenever possible.

Security protections may include:

  • TLS-encrypted communications
  • Encrypted storage services
  • Access auditing
  • Role-based permissions
  • Environment isolation controls

🌐Network Security Policy

Velantix Axiom's network architecture is designed so that internal processing systems are never directly reachable from the public internet.

  • Public traffic terminates at a managed, global edge network before reaching any internal system
  • Assessment processing infrastructure runs in a private, isolated network with no public IP address and no open inbound ports
  • Administrative access to processing infrastructure is performed through short-lived, authenticated, and logged connections rather than direct network access
  • Network boundaries are isolated per engagement, limiting the scope of any single environment
  • All traffic in transit is encrypted using TLS

🔒Encryption Policy

Encryption is applied across the full lifecycle of assessment data — in transit, at rest, and during processing.

  • All data in transit is encrypted using TLS, including portal sessions, file uploads, and internal service-to-service communication
  • Customer inventory data, generated deliverables, and audit records are stored using encrypted storage services
  • Encryption keys are managed through a dedicated key management service, with regional key isolation available for engagements with data residency requirements
  • Application secrets and credentials are stored in a managed secrets service and retrieved at runtime — never embedded in source code or machine images
  • Encryption configuration is applied consistently through infrastructure-as-code rather than manual setup, so protections cannot be silently disabled or drift over time

👤Access Controls

Administrative and operational access to platform systems is restricted to authorized personnel based on operational responsibilities.

Authentication and access management practices are designed to minimize unauthorized access risk.

🖥️Endpoint & Physical Security

Administrative access to the platform is protected at the device, credential, and facility level, not just at the network boundary.

  • Administrative devices run continuous endpoint protection, including antimalware, antiphishing, and advanced threat detection, with automated compliance and security audit reporting on a regular schedule
  • Administrative and cloud provider credentials are managed through a dedicated password manager with unique, high-strength passwords and continuous compromise monitoring
  • Administrative network access operates behind a dedicated firewall with no open inbound ports
  • The facility housing administrative equipment is protected by monitored surveillance and access-logged entry controls

🤖AI and Data Handling

AI-assisted analysis capabilities are designed to operate on infrastructure telemetry, configuration metadata, and assessment-related operational data. Every Axiom assessment combines AI-assisted analysis with expert architectural validation.

Velantix LLC does not intentionally use uploaded customer assessment data for public AI model training.

🧪Secure Development Practices

Velantix LLC incorporates security considerations into platform architecture, code review processes, change management, dependency management, and infrastructure deployment workflows.

🚨Responsible Disclosure

If you believe you have identified a security issue or vulnerability, please contact:

[email protected]

Please include:

  • Description of the issue
  • Steps to reproduce
  • Relevant screenshots or logs if applicable

Velantix LLC appreciates responsible disclosure practices and will investigate reported concerns promptly.

🧭Future Compliance Roadmap

Velantix LLC is designing operational and platform processes with future enterprise and regulated-environment readiness in mind, including alignment toward security best practices, enterprise governance expectations, and government and regulated industry requirements.