Last updated 12 June 2026
The strongest security control in V3LA is architectural: most of your data never leaves your phone, so most of it is never ours to lose. What we do hold is described below, along with the state of our compliance work — including the parts that aren't finished.
Observation window underway; report expected within the year.
Annual, app and API. Summary available under NDA.
V3LA is not a covered entity and does not process PHI on behalf of one. We say so rather than implying coverage.
Security questionnaires, architecture diagrams and the pen-test summary are available to enterprise prospects under NDA.
Write to security@v3la.com with enough detail to reproduce. We acknowledge within one working day, give you an assessment within five, and keep you updated until it's closed.
Safe harbour. We will not pursue legal action against researchers who act in good faith, avoid accessing other users' data, don't degrade the service, and give us reasonable time to fix an issue before disclosure.
We pay bounties for valid findings, scaled to severity, and we credit reporters publicly unless you'd rather we didn't.
In the event of a breach affecting your data, we will notify affected users directly within 72 hours of confirmation, publish what we know, and say plainly what we don't yet know. We'd rather post an incomplete update quickly than a polished one late.
Enterprise reviews, questionnaires and disclosures all start here.
Contact us