Trust

Security at Velora

A deliberately small data footprint for a read-only Salesforce app.

Salesforce-native architecture

Velora PublicLink Control Lite runs inside the subscriber’s Salesforce organisation. It has no external callouts, connected apps, named credentials, third-party processors, or analytics pixels.

Data handling

The app does not store file bodies, password values, public URLs, or download URLs. App settings and current scan findings stay inside the customer’s Salesforce organisation.

Access and behaviour

Access is controlled using Salesforce permissions. Lite scans are started manually and are read-only: the app does not change, expire, or revoke public links.

Report a security issue

Please email security@veloraapps.net with a clear description and steps to reproduce. Do not include live credentials, passwords, public URLs, or customer data.