Trust · security

Security at Veya

Your business runs its conversations, contacts and documents through Veya. Here is how we protect them — in plain language, with no claims we can't stand behind.

Updated
August 2, 2026
Applies to
The Veya platform & services
Report an issue
admin@veya.com.my

1. Infrastructure

Veya runs on managed cloud infrastructure: application servers and managed databases on DigitalOcean, object storage and network security on Cloudflare, and managed Redis on Upstash. We do not operate physical servers; the underlying providers maintain industry-standard physical and environmental security for their data centers.

Services run in minimal, hardened container images with no shell and no package manager, reducing the attack surface of the runtime itself.

2. Encryption

All traffic — between your browser and Veya, between Veya services, and between Veya and the messaging platforms — is encrypted in transit using HTTPS/TLS. There are no unencrypted endpoints.

Sensitive credentials — API tokens, integration keys, and access secrets — are encrypted at rest using envelope encryption (AES-256-GCM) and are never stored in code or configuration files. Sensitive values are redacted from application logs.

3. Tenant isolation & access control

Every record in Veya belongs to exactly one organization. Isolation is enforced consistently at the application layer: every query is scoped to the requesting organization, and cross-tenant access paths are covered by automated checks in our development process.

Within an organization, access follows role-based permissions (owner, admin, member). Inbox access can additionally be restricted per channel and per phone number, so team members only see the conversations assigned to them. Administrative actions are audit-logged.

4. Your data stays yours

The data you bring to Veya — contacts, conversations, documents — belongs to you. We do not sell it, we do not share it with advertisers or data brokers, and our AI features run on an inference-only basis under provider terms that prohibit training on your data (see our Privacy Policy).

For AI analytics, Veya supports pseudonymisation: customer and contact names can be replaced with opaque tokens before anything is sent to an AI provider, and translated back to real names only in your browser — so the provider never receives who your customers are, only the figures needed to answer your question.

You can export your organization’s data (contacts and conversations across all channels, as machine-readable CSV archives) from your workspace settings at any time, and request deletion when you leave. Your WhatsApp numbers remain portable under Meta’s standard process — there is no technical lock-in.

5. Subprocessors

We share data only with the service providers required to operate the platform:

  • DigitalOcean — application hosting & managed databases
  • Cloudflare — object storage (R2) and network security
  • Upstash — queue and cache infrastructure
  • Meta Platforms — WhatsApp Business message transport
  • Resend — transactional (system) email delivery
  • Tinybird — analytics infrastructure backing business-intelligence features; data is tenant-tagged and queried only through short-lived, organization-locked access tokens
  • Google, OpenAI, Anthropic — AI inference only, for features you actively invoke; no training on customer data

We update this list when providers change; material changes are communicated to affected customers.

6. Incident response

If a security incident affects your data or service, we notify affected customers promptly with what happened, what data was involved, and what we are doing about it — followed by a written report. Contractual customers have defined notification windows in their agreements.

7. Reporting a vulnerability

We welcome reports from security researchers. If you believe you have found a vulnerability in Veya, email admin@veya.com.my with enough detail to reproduce the issue. We commit to acknowledging reports quickly, keeping you informed while we fix the issue, and never pursuing legal action against good-faith research. Machine-readable contact details are published at /.well-known/security.txt.

8. Questions

Security questionnaires, supplier assessments, or anything this page doesn’t answer: contact admin@veya.com.my and we’ll respond with specifics for your engagement.