Trust center

Security boundaries you can evaluate

A practical summary of what Veil protects, what the cloud processes, who supports the service and where the product’s limits remain.

Last reviewed: 14 July 2026 · Applies to Veil 1.5

Core security model

Local protection

Detection, masking, encryption and decryption run in the browser. Veil uses AES-GCM with PBKDF2-derived keys for local protected text.

Customer-held passphrases

Personal and Business passphrases are retained locally and are not uploaded, synchronized or recoverable by Goldspire.

Verified browsers

Every Personal or Business browser using cloud features requires mailbox approval. Business administrators can revoke browsers individually.

Cloud data boundaries

  • Processed: account email, organization membership, device approval, policy settings, encrypted token/share blobs, billing references, support submissions and optional metadata-only Business events.
  • Rejected or excluded: matched plaintext, decrypted content, full message bodies, full prompts and customer-held passphrases.
  • Organization events: may include category, severity, host, action, confidence, member and device identifiers, but not the matched value.
  • Personal learning: Copilot decisions remain local in Veil 1.5 and are not uploaded to Goldspire.
  • Protection updates: validated before use and rejected when authenticity cannot be established.

Detection coverage and limits

Veil looks for high-confidence credentials, payment and banking details, contact information, government and health identifiers, and customer or internal references. Common casing, spacing and separator variations are supported for many structured formats.

  • Browser text fields: protection applies when you type, paste or select text in supported Chrome and Edge web fields and editors.
  • Global formats: Veil supports all current SWIFT IBAN country lengths and a growing set of national identifiers. It does not claim every identifier, language or country-specific format.
  • Not inspected in 1.5: attachment contents, images or scans, audio, native desktop/mobile applications and unsupported custom or canvas-based editors. Supported AI sites can warn or block the file action without reading the file.
  • Safety boundary: detection can miss sensitive information or flag a benign lookalike. Veil assists the user; it does not replace judgment or an organization’s other security controls.

View the versioned 1.5 coverage and compatibility catalogue.

Service providers

ProviderPurposeTypical data
CloudflarePortal delivery, DNS, TLS and edge securityIP address and request metadata
RailwayAPI hosting and application runtimeAccount, organization, policy, support and event metadata processed by the API
SupabaseManaged PostgreSQL databaseAccounts, approvals, policies, ciphertext, billing references and security metadata
StripeSubscription checkout and billingCustomer, subscription and payment information; Goldspire does not store full card details
Brevo / ResendTransactional emailRecipient email, verification or invitation content and delivery metadata
Anthropic (Goldspire Support AI)Policy-bound support classification and reply draftingSubmitted support message and safe diagnostic metadata; contact email is excluded from model input where practical
OpenAI (optional alternative)Support classification and reply drafting only when explicitly selected by GoldspireThe same minimized support message and safe diagnostic metadata
GitHubPrivate source control and release automationSource code, CI logs and development metadata; production customer content is not intentionally stored there

Customer-configured SIEM or identity destinations are controlled by the customer and are not Goldspire subprocessors for that independent use.

Default retention

Data classDefault retention
Browser approval tokens24 hours or successful approval
Revoked or expired join codes90 days
Revoked browser records12 months, unless needed for a security investigation
Security-event metadata90 days by default
Encrypted token/share blobsConfigured expiry or read limit; maximum 90 days unless contractually extended
Support tickets24 months after closure
Operational request metrics30 days
Database backups35 days
Billing recordsContract term plus statutory accounting/tax period where required

Operational security

Release controls

Veil releases pass security, compatibility and customer-journey checks before packaging.

Incident response

Goldspire maintains incident classification, containment, evidence, notification and recovery procedures for Veil operations.

Backup and recovery

Production readiness includes managed backups, restore procedures and recorded recovery exercises.

Compliance posture

Veil includes policy context for GDPR, PCI DSS, HIPAA, SOC 2 and ISO 27001-aligned workflows. These mappings are product guidance; they do not make a customer compliant and do not represent certification of Goldspire or Veil.

Enterprise customers may request the available security and procurement materials from Sales.

Report a vulnerability

Send security reports privately. Include the affected feature, reproduction steps and potential impact. Do not access other users’ data or run disruptive testing.