What Velatir Stores
For every interaction, Velatir keeps the context it needs to monitor AI usage and produce an audit trail. The raw prompt is reviewed in memory. It is written to storage only if you choose When flagged or Always — under Never, it never hits disk. See Data privacy for those settings and for retention.Encryption at Rest
All stored data is encrypted at rest — summaries, metadata, and any raw session content — whether or not you bring your own key. The disk encryption is AES-XTS-plain64 with SHA-256 and a 512-bit key size.Encryption in Transit
All traffic to Velatir is encrypted with TLS.Your Own Keys
Optionally, encrypt stored session content with a key your organisation holds. Velatir keeps only the public key. The private key never leaves your side, and content is decrypted in the browser. Each stored field is encrypted with AES-256-GCM; the content key is wrapped with your RSA public key (RSA-OAEP).Your keys
Create an encryption key in Settings → General → Data & privacy. Only the public key is stored by Velatir.
Decrypt in the browser
Open a trace, go to Context, and choose Decrypt. Paste or upload your private key. Velatir never receives it.
Create a key
In Data & privacy, choose Create encryption key. The key pair is generated in your browser. Give it a label and generate it.
Save the private key
Copy it or Download .pem. It is shown once. Confirm with I have saved my key.
Activate it
Activate the key so new stored content is encrypted to it. The badge reads Encryption enabled.
Decrypt when you need to read it
On a trace, the Context tab shows Context encrypted. Choose Decrypt, paste or upload the
.pem, and optionally Remember on this device. The content is decrypted locally as Context decrypted.Customer keys protect stored Context. Velatir still reviews the interaction in order to apply your agents. The Description, service, timestamps, and assessments are not encrypted to your key — they stay available so the product can show activity.
Tenant Isolation
Every organisation’s data is separated at the data layer. Your traces, sessions, and settings are scoped to your organisation, and there is no path for one organisation to reach another’s data.Retention
If you set a bounded data retention period, records older than that window are deleted automatically each day. That includes the Description, assessments, and any stored raw content. The default, Always, does not delete on a schedule. Changing to a bounded period waits seven days before the first deletion. Settings shows the next deletion date.Data Exports
You can request an export of your data under Settings → Data exports. This supports your own record-keeping and helps you respond to data subject requests under GDPR.Data privacy
Storage modes, summaries, retention, and access controls.
Organisations & workspaces
How your account is structured.