Security & Compliance

Security is foundational to Velo. This statement summarises the technical and organisational controls we apply to protect payments and data.

Encryption in transit — TLS 1.2+

All traffic to and from the platform is served exclusively over HTTPS. Connections are encrypted using TLS 1.2 or higher; legacy TLS 1.0/1.1 and insecure ciphers are not accepted. HTTP requests are redirected to HTTPS and HSTS is enforced with preload.

Integrity — SHA-256

Modern, secure hashing (SHA-256) is used for file integrity and verification, and signed session tokens use strong algorithms. Deprecated algorithms such as MD5/SHA-1 are not used for security-relevant operations.

PCI DSS — minimal scope

Velo never collects, stores or transmits full card numbers or CVV. Card data is captured in PCI-DSS-compliant hosted fields provided by our regulated payment partner, keeping the integration eligible for SAQ A. 3-D Secure / SCA is enforced.

Data protection & KYC documents

Personal data and uploaded verification (KYC) documents are stored on access-controlled infrastructure, are private by default, and are accessible only to authorised compliance reviewers. Images are re-encoded and metadata-stripped on upload. Access is least-privilege and audit-logged.

Report a vulnerability or ask a security question: support@velopay.app