Security & compliance

Built for a regulated profession.

Trust isn't declared : it's engineered. Every guarantee below is a verifiable technical choice, not a marketing promise.

The Alur Act No. 2014-366 (French housing law) The Hoguet Act No. 70-9 (French real-estate agents law) GDPR (EU) 2016/679

Read-only, non-intrusion & human validation

Ghost mode: absolute read-only on your tools

Velum reads your e-mails and your business tools without ever modifying, marking as read or moving anything. Proven on a real mailbox : a message read by Velum stayed « unread » on the server side.

Velum prepares, you send

A suggested reply is only saved as a reversible draft, after two validations on your part ; you open it and send it yourself. Velum never sends on your behalf.

Read-only bank connection

Rent bank reconciliation only reads balances and transactions : no payment transfer can be initiated, by the very design of the connector (PSD2-authorised access).

Protected access for your clients

The landlord/owner, tenant and co-owner portals open via a single-use link, hashed in the database, with an identical response whether or not the account exists — making it impossible to guess who is a client.

Nothing irreversible without your validation

No binding action is carried out on its own : reminders, minutes, calls for funds and signatures are proposed in passive mode and only exist after your explicit decision.

Data protection & artificial intelligence

No personal data in clear text reaches the AI

Names, e-mails, phone numbers, addresses, IBANs, SIRET numbers are replaced by anonymous tokens before any call to the AI. Your data is never used to train the AI.

Every firm hermetically compartmentalised

Pseudonymisation tokens are unique to each firm : the same name yields a different token from one client to another. No cross-referencing of data between firms is possible.

Anti-leak safety net verified continuously

After each pseudonymisation, an automatic check re-scans the text and raises an alert if a sensitive pattern slipped through — without ever recording the value, only a counter.

AES-256 encryption, column by column

Names, e-mails, phone numbers, IBANs, security deposits are encrypted individually in the database. Even a copy of the database stays unreadable without the key.

We only collect the strict minimum

Mailbox history is never harvested (new messages only), the AI receives only lot numbers and amounts, and encrypted data is decrypted only when a specific record is opened.

Logs, traceability & retention

Zero personal data in the logs

Technical logs are filtered at two levels — by field name and by content scanning — to mask e-mails, IBANs and phone numbers, even when slipped into an error message.

Tamper-proof traceability of sensitive actions

Every critical action (validation, signature, export, purge, consent) is written to a register that the database itself prevents from being modified or erased.

Encrypted backups tested every night

Every night : full backup, real restore test, encryption, then off-site storage. The decryption key stays in an offline vault, never on the server.

Automatic deletion of expired data

Expired data is purged without intervention : pseudonymisation tokens at 30 days, inactive buyers at 12 months, used links, inventory-of-fixtures photos at 5 years.

Consents traced and revocable

Every consent is time-stamped and logged, with the option to revoke it at any time, for a complete audit of how it was collected.

Sovereignty, access & legal framework

Sovereign hosting in France (OVHcloud)

Your data is hosted on French and European infrastructure, with full-text search and indexing that are 100 % local — no dependency on a non-European cloud.

Sub-processors bound by contract

Every technical provider is covered by a data processing agreement (DPA) and, for flows outside the EU, by the European Commission's Standard Contractual Clauses (SCC art. 46).

Representative appointed in the European Union

Velum has appointed a representative established in the EU, a point of contact for data subjects and supervisory authorities (GDPR art. 27).

Breach notification procedure ready

An incident management plan enables notification to the CNIL (French data protection authority) within 72 h and informing data subjects where required (GDPR art. 33-34).

Secrets and keys never versioned

Encryption keys, credentials and the private banking key live outside the source code and are never committed to the repository.

Hardened authentication and sessions

Short-lived access tokens kept in memory (never stored persistently in the browser), refresh via a secure HttpOnly cookie, passwords hashed with bcrypt.

Protection against abuse and scraping

Request throughput is capped per IP and e-mail searches go through a hashed index, which neutralises harvesting or enumeration attempts.

Questions about security ?

We provide the data processing agreement (DPA), the security fact sheet (technical and organisational measures) and respond to your compliance requirements before any commitment.