Built for a regulated profession.
Trust isn't declared : it's engineered. Every guarantee below is a verifiable technical choice, not a marketing promise.
Read-only, non-intrusion & human validation
Ghost mode: absolute read-only on your tools
Velum reads your e-mails and your business tools without ever modifying, marking as read or moving anything. Proven on a real mailbox : a message read by Velum stayed « unread » on the server side.
Velum prepares, you send
A suggested reply is only saved as a reversible draft, after two validations on your part ; you open it and send it yourself. Velum never sends on your behalf.
Read-only bank connection
Rent bank reconciliation only reads balances and transactions : no payment transfer can be initiated, by the very design of the connector (PSD2-authorised access).
Protected access for your clients
The landlord/owner, tenant and co-owner portals open via a single-use link, hashed in the database, with an identical response whether or not the account exists — making it impossible to guess who is a client.
Nothing irreversible without your validation
No binding action is carried out on its own : reminders, minutes, calls for funds and signatures are proposed in passive mode and only exist after your explicit decision.
Data protection & artificial intelligence
No personal data in clear text reaches the AI
Names, e-mails, phone numbers, addresses, IBANs, SIRET numbers are replaced by anonymous tokens before any call to the AI. Your data is never used to train the AI.
Every firm hermetically compartmentalised
Pseudonymisation tokens are unique to each firm : the same name yields a different token from one client to another. No cross-referencing of data between firms is possible.
Anti-leak safety net verified continuously
After each pseudonymisation, an automatic check re-scans the text and raises an alert if a sensitive pattern slipped through — without ever recording the value, only a counter.
AES-256 encryption, column by column
Names, e-mails, phone numbers, IBANs, security deposits are encrypted individually in the database. Even a copy of the database stays unreadable without the key.
We only collect the strict minimum
Mailbox history is never harvested (new messages only), the AI receives only lot numbers and amounts, and encrypted data is decrypted only when a specific record is opened.
Logs, traceability & retention
Zero personal data in the logs
Technical logs are filtered at two levels — by field name and by content scanning — to mask e-mails, IBANs and phone numbers, even when slipped into an error message.
Tamper-proof traceability of sensitive actions
Every critical action (validation, signature, export, purge, consent) is written to a register that the database itself prevents from being modified or erased.
Encrypted backups tested every night
Every night : full backup, real restore test, encryption, then off-site storage. The decryption key stays in an offline vault, never on the server.
Automatic deletion of expired data
Expired data is purged without intervention : pseudonymisation tokens at 30 days, inactive buyers at 12 months, used links, inventory-of-fixtures photos at 5 years.
Consents traced and revocable
Every consent is time-stamped and logged, with the option to revoke it at any time, for a complete audit of how it was collected.
Sovereignty, access & legal framework
Sovereign hosting in France (OVHcloud)
Your data is hosted on French and European infrastructure, with full-text search and indexing that are 100 % local — no dependency on a non-European cloud.
Sub-processors bound by contract
Every technical provider is covered by a data processing agreement (DPA) and, for flows outside the EU, by the European Commission's Standard Contractual Clauses (SCC art. 46).
Representative appointed in the European Union
Velum has appointed a representative established in the EU, a point of contact for data subjects and supervisory authorities (GDPR art. 27).
Breach notification procedure ready
An incident management plan enables notification to the CNIL (French data protection authority) within 72 h and informing data subjects where required (GDPR art. 33-34).
Secrets and keys never versioned
Encryption keys, credentials and the private banking key live outside the source code and are never committed to the repository.
Hardened authentication and sessions
Short-lived access tokens kept in memory (never stored persistently in the browser), refresh via a secure HttpOnly cookie, passwords hashed with bcrypt.
Protection against abuse and scraping
Request throughput is capped per IP and e-mail searches go through a hashed index, which neutralises harvesting or enumeration attempts.
Questions about security ?
We provide the data processing agreement (DPA), the security fact sheet (technical and organisational measures) and respond to your compliance requirements before any commitment.