Series A · circadian performance systems V3LA One — clinical validation underway
Legal

Security

Last updated 12 June 2026

The strongest security control in V3LA is architectural: most of your data never leaves your phone, so most of it is never ours to lose. What we do hold is described below, along with the state of our compliance work — including the parts that aren't finished.

Controls in place

On-device by default
Phase inference and raw series stay in the app's protected container. Cloud backup is opt-in and not required for any feature.
Encryption
TLS 1.3 in transit; AES-256 at rest. Backed-up series are encrypted with a key derived on your device, so a server-side compromise does not yield readable measurements.
Device link
BLE pairing with per-device keys and encrypted characteristics. Firmware updates are signed; the bootloader rejects unsigned images.
Access control
Least privilege, hardware-key MFA for all staff, and no standing production access — elevation is time-boxed and logged.
Segregation in enterprise
Roster Engine computes aggregates without exposing individual records to the customer tenant, and suppresses output below a minimum group size.

Compliance status

In progress
SOC 2 Type II

Observation window underway; report expected within the year.

Complete
External penetration test

Annual, app and API. Summary available under NDA.

Not applicable
HIPAA

V3LA is not a covered entity and does not process PHI on behalf of one. We say so rather than implying coverage.

Security questionnaires, architecture diagrams and the pen-test summary are available to enterprise prospects under NDA.

Reporting a vulnerability

Write to security@v3la.com with enough detail to reproduce. We acknowledge within one working day, give you an assessment within five, and keep you updated until it's closed.

Safe harbour. We will not pursue legal action against researchers who act in good faith, avoid accessing other users' data, don't degrade the service, and give us reasonable time to fix an issue before disclosure.

We pay bounties for valid findings, scaled to severity, and we credit reporters publicly unless you'd rather we didn't.

If something goes wrong

In the event of a breach affecting your data, we will notify affected users directly within 72 hours of confirmation, publish what we know, and say plainly what we don't yet know. We'd rather post an incomplete update quickly than a polished one late.

Security or compliance contact

Enterprise reviews, questionnaires and disclosures all start here.

Contact us