About these measures
These are the technical and organisational measures (TOMs) we apply to protect personal data, appropriate to the risk and the nature of the service. Velocity is provided by Kevin Klein, together with the service providers that operate the platform; the measures below describe the platform as it is built today. They form part of our Data Processing Agreement.
Access control and authentication
- User accounts are protected by our database and authentication provider, using email and password sign-in (and optional identity-provider sign-in where enabled).
- Administrative functions are restricted to authorised administrator roles and protected by route-level access checks.
- Access to production systems and provider consoles is limited to the operator.
Tenant separation and authorisation
- Data is scoped to a workspace, and access is restricted to that workspace's members and roles.
- Database access is enforced by row-level security policies at the database layer, in addition to application checks.
Encryption in transit
- Web and API traffic is served over HTTPS/TLS.
- Real-time signalling uses secure WebSockets (WSS), and real-time audio and video use WebRTC with DTLS-SRTP.
Encryption at rest
- Object storage buckets holding recordings and uploads are private and rely on the provider's server-side encryption at rest.
- The managed database is encrypted at rest by the provider.
Recording and content protection
- Recordings are stored privately. Shared recordings are delivered through short-lived, access-controlled links rather than public storage URLs, and links are re-issued on each access.
- Recording is controlled by the Host and does not run unless the Host starts it.
Secrets management
- Third-party restreaming stream keys are stored encrypted in a managed secrets store and are not returned to the browser.
- Server credentials are held in provider environment/secret stores and are not committed to source code.
Logging and monitoring
- Operational event logs are kept for security and troubleshooting; IP addresses are redacted in these logs.
- Application errors are captured by an error monitoring provider; session replay is not enabled.
Availability, backup, and deletion
- The managed database provider maintains platform-level backups of the database.
- Recordings are removed automatically at the end of their retention period, and account data is deleted or anonymised within 90 days of account closure, subject to legal retention.
Incident handling
If we become aware of a personal data breach, we assess it and, where required, notify the competent supervisory authority and affected controllers or individuals in line with Arts. 33 and 34 GDPR. Report a suspected incident to legal@velocitystreaming.io.
What we do not claim
Velocity does not currently hold ISO 27001 or SOC 2 certification and does not provide end-to-end encryption. These measures will be updated as the service develops.