velsa

Security and compliance, built in from day one.

Velsa is built by Palladium Innovations, LLC — a federal-software firm with direct experience shipping under the DoD Risk Management Framework at Information Protection Levels 2 through 6. The same engineering discipline shapes Velsa.

Last updated: 15 June 2026

Compliance roadmap

Where Velsa is heading. Specific timelines firm up as we approach each milestone.

On the roadmap

SOC 2 Type II

Architecture is being built against the Trust Services Criteria from day one. Audit engagement begins post-private-beta.

By design

PCI DSS

Velsa does not directly process card data. Payment flows route through a PCI-compliant processor.

Long-term path

FedRAMP

Underlying infrastructure is built on a FedRAMP-aligned, AWS-hardened deployment, leveraging Palladium's existing federal-software experience.

Security practices

Velsa is engineered to a government security standard — not bolted on afterward. What follows is in place today, backed by code, configuration, and maintained evidence.

In place today

On the roadmap

Data handling

Where data lives

Customer data is stored in Amazon Web Services US-East (Northern Virginia). Backup copies are encrypted and retained within the same region. Data does not leave AWS infrastructure.

What we collect

Velsa is built to manage events at venues. The product collects what's necessary to do that: contact information for attendees and counterparties, contract and booking details, financial transactions related to events, and operational data about how venues are run.

What we don't do

Retention and deletion

Data is retained for the life of your account. On account deletion, customer data is permanently removed within 30 days, except where retention is required by law or regulation.

Export

Scoped exports — accounting and ledger data, and individual reports in CSV, Excel, and PDF — are available in the product today. A full self-service account export is on the roadmap; in the meantime, a complete export can be arranged on request.

Sub-processors

Velsa relies on the following third parties to deliver the product. This list is updated as the product evolves.

Incident response

Velsa monitors infrastructure and application health continuously. In the event of a security incident:

  1. Detection via CloudWatch alarms, application logs, and customer reports.
  2. Triage by the engineering team within one business hour of detection.
  3. Affected customers are notified within 72 hours of confirmed incident, in line with industry best practice.
  4. Post-incident review documents root cause, customer impact, and corrective actions.

Responsible disclosure

If you've found a security issue in Velsa, please report it to security@velsa.io. Our full policy — scope, response times, and safe-harbor terms — lives on the security & disclosure page, and is also published in machine-readable form as security.txt. The summary below covers the essentials.

In scope

Out of scope

Our commitments

Please don't

Documents

Available now, or as Velsa matures:

Questions?

Anything covered on this page — or anything we should add to it.