Skip to content

Security

Read-only connections. Your data produces your analysis only.

Vael connects to your accounts to read, not to write. This page covers how we protect your data, what we do with it, and where our compliance posture stands today, honestly.

Read-only connections. Never moves money.
TLS 1.2+ in transit, AES-256 at rest.
Your data produces your analysis only.
Delete your data anytime from settings.
01Data handling

Encrypted, isolated, yours

Your financial data is encrypted in transit and at rest. It is used to produce your analysis and nothing else.

In transit

TLS 1.2+ everywhere

All data moving between your browser, your connected accounts, and Vael's servers travels over TLS 1.2 or higher. There is no unencrypted path into or out of the system.

At rest

AES-256 at rest

Your financial data and analysis results are encrypted at rest with AES-256 across all storage layers. Encryption is applied at the infrastructure level, not as an optional setting.

Data ownership

Your data, your analysis only

The numbers you provide produce your analysis and only your analysis. Your data is not sold. Model providers are contractually prohibited from using it to train or improve shared models.

Tenant isolation

Isolated by design

Each account's data and analysis results are isolated at the application and storage layers. No query, report, or API call can return another account's data.

02Account connections

Vael reads your accounts. It cannot write to them.

When you connect a bank account, a card, or an invoicing tool, the connection is made through that provider's read-only OAuth flow. Vael receives a read-only access token. It does not receive your credentials and it cannot request a broader scope after the fact.

What read-only means in practice

  • Vael can pull transaction history, balances, and invoice data.
  • It cannot initiate transfers or payments.
  • It cannot approve, reject, or modify any transaction.
  • It cannot add, remove, or change payees.
  • It cannot change your account settings at the provider.

Revoking access

You can disconnect any account from Vael's settings page at any time. You can also revoke the token directly from the provider (your bank, Plaid's dashboard, or your invoicing tool). Either action immediately ends Vael's read access.

Paste instead of connect

If you prefer not to connect an account, you can paste numbers directly. A CSV export, a bank statement table, or a hand-typed list of expenses all work. Nothing is stored from a paste-based read unless you explicitly save the analysis.

03Access and secrets

Least privilege, by default

No standing access to customer data. Secrets never in source code. Sessions terminate cleanly.

Least privilege access

Vael engineers do not have standing access to customer data. Access to production data requires an explicit, time-bounded grant, approved by a second party, reviewed on completion.

Secrets management

API keys, database credentials, and third-party tokens are stored as encrypted environment variables. They are never in source code or client bundles. Rotation follows a defined schedule.

Read-only account connections

When you connect a bank or invoicing account through Plaid, Stripe, or a similar provider, the connection is read-only. Vael cannot move money, approve payments, or write back to your accounts.

No credential storage

Vael never stores bank credentials. Connections go through the provider's OAuth flow. The provider issues a read-only access token. You can revoke that token from the provider's side at any time.

Server-side model calls

Model provider API keys live only in server-side environment variables. They are never in the client bundle. The model call is made from the server, not the browser.

Session security

Sessions are managed with HTTP-only, secure, SameSite cookies. Tokens are never exposed to JavaScript. Sessions expire and can be terminated from account settings.

04Compliance

Where we stand, honestly

Vael is a pre-seed startup. We state our compliance position as it is, not as we would like it to appear. Where something is in progress, we say so. We do not list certifications we have not yet received.

SOC 2 Type II

Our SOC 2 Type II audit is on our 12-month roadmap. We are building toward it now: access controls, audit logging, and incident response procedures are being documented and tested. We expect to engage an accredited auditor in the next 6 to 9 months. Customers who need our current controls documentation in the meantime may request it at security@vaelfinance.com.

Data residency

Vael is hosted on Vercel infrastructure and data is stored in the United States. We do not currently offer EU or UK data residency. This is on our roadmap. If US-only residency is a blocker for your evaluation, please contact us.

CCPA

We process personal data only as needed to provide the service. You have the right to request a copy of your data, to correct it, and to delete it. To exercise these rights, write to hello@vaelfinance.com.

SOC 2 roadmap
Access controls documented and testedcomplete
Audit logging in place for data access eventscomplete
Incident response procedure writtencomplete
Security awareness training for all staffin progress
Vendor risk assessments for subprocessorsin progress
Engage accredited SOC 2 auditorplanned
SOC 2 Type II report issuedplanned
05Subprocessors

Who touches your data, and how

A small, fixed list. Every subprocessor is assessed before use and is contractually bound to our data handling requirements.

OpenAI

Model provider

Language model inference for financial reads. Data sent: the numbers you provide. Usage: not used to train shared models per API terms.

Privacy policy

Anthropic

Model provider (optional)

Alternate model provider, activated when an Anthropic API key is configured. Same data handling rules as OpenAI.

Privacy policy

Vercel

Hosting and edge runtime

Application hosting, serverless functions, and edge delivery. Data remains in US regions by default.

Privacy policy

Plaid

Bank data provider (read-only)

Read-only bank and card transaction data, when you authorize a connection. Vael uses Plaid's OAuth; your banking credentials go to Plaid, not to Vael.

Privacy policy
06Data retention and deletion

Your data, on your terms

What is stored and for how long

When you save an analysis, the result (figures, leaks, cuts, anomalies, the plain-language summary) is stored in your account. The raw numbers you pasted or the transaction export you authorized are stored only for the duration of the analysis and are not retained separately.

Deleting an analysis

You can delete any saved analysis from your account at any time. Deletion removes the result from your account and from our storage. It is permanent.

Deleting your account

You can delete your account from settings. Account deletion removes your profile, all saved analyses, and all connected account tokens. A confirmation email is sent when deletion is complete. We do not retain your data after deletion.

Inactive accounts

If your account is inactive for 24 months, we will notify you by email before taking any action on your data.

07Responsible disclosure

Found something? Tell us.

If you find a security vulnerability in Vael, we want to know about it. We take every report seriously.

How to report

Email security@vaelfinance.com with a description of the issue, steps to reproduce, the environment (browser, OS, account type), and any relevant logs or screenshots. We do not require a specific format.

What to expect

  • Acknowledgment within one business day.
  • A status update within 7 days, including whether the report is confirmed.
  • Progress updates every 30 days on confirmed issues.
  • Resolution of confirmed issues within 90 days for most severity levels.

Scope

In scope: vaelfinance.com and its subdomains, the Vael web application and API. Out of scope: social engineering, physical security, and third-party services not operated by Vael.

08Common questions

Security questions

A read you can trust, on data that stays yours.

Start free, no card. Vael connects read-only and reads your runway, your leaks, and your next move in plain language.