Trust

Security & Compliance

Last updated: September 4, 2026 Applies to: healthvela.com, the Vela web app, waitlist, and related services

What we protect today
Honest limits (so you are not surprised)
Contents
  1. Overview
  2. Infrastructure security and reliability
  3. Data security and privacy
  4. AI and health data commitments
  5. Secure development practices
  6. Vulnerability disclosure
  7. Contact

01

Overview

We store and process user data according to our Privacy Notice and Terms & Conditions. Technical and organizational measures include encryption in transit, hashed passwords, least-privilege access, private object storage for uploads (when enabled), rate limiting, and protective HTTP headers.

02

Infrastructure security and reliability

Cloud platform security

Vela’s marketing site and related serverless delivery are hosted on Vercel. Application and API backends are hosted on Railway (or equivalent cloud hosts). Account and health data are stored in managed PostgreSQL databases operated by our cloud host. Optional file uploads are stored in private, non-public S3-compatible object storage with server-side encryption (AES-256) when that feature is enabled.

We rely on these providers’ physical and network security controls and configure our services to use HTTPS, private storage buckets (no public access), and authenticated database access.

Reliability

We strive to maintain high operational availability of our products and services. Planned maintenance or incidents may occasionally affect availability; we work to restore service promptly.

03

Data security and privacy

User data

User data is stored and processed securely according to our Privacy Notice and Terms. Account data is tied to your user ID and requires authentication. Employee and contractor access is limited to what is needed to operate the Services.

Health information

Health and lifestyle information you choose to share is treated as sensitive. We do not sell your personal information. We do not share user questions or conversations. We do not train AI models on protected health information (PHI). Educational guidance is informed by published research, not your PHI. See the Privacy Notice for details.

Data encryption

These controls help ensure that unauthorized parties cannot easily read data in transit or access passwords in recoverable form. Absolute security cannot be guaranteed for any internet service.

04

AI and health data commitments

05

Secure development practices

We take care to design and ship features with security in mind, including:

We do not currently claim SOC 2 certification. If we complete independent audits or additional certifications in the future, we will update this page with accurate status.

06

Vulnerability disclosure

We take reports of security vulnerabilities seriously and will respond to valid reports as we verify the issue and develop a fix. Researchers can also find contact details in /.well-known/security.txt. Please report vulnerabilities and security concerns responsibly to info@healthvela.com with subject “Security Vulnerability.” Include a clear description and, where possible, reproducible steps or a proof of concept that does not exploit production data beyond what is needed to demonstrate the issue.

Please do not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and remediate. Bug bounties, if offered, are at our discretion for confirmed medium-or-higher severity issues.

07

Contact

Questions about security or this page: info@healthvela.com (subject: Security).

Vela Wellness, LLC (operating as Vela Health)
Attn: Security / Privacy
Email: info@healthvela.com
For a current registered mailing address, email with subject “Mailing Address Request.”

© Vela Wellness, LLC · Operating as Vela Health. This page describes current practices and is not a warranty of uninterrupted security or a claim of HIPAA or SOC 2 certification unless expressly stated above.