Veela holds your registers, your minute book and your ASIC corporate key. That's not a responsibility we take on with marketing language — this page describes the controls that are actually built, in plain terms.
Nothing circulates, writes to a register or goes near ASIC without a named person's approval. Every AI draft passes an independent checker first, and drafts are clearly framed as unreviewed until a human signs off. Veela is built so the accountable officer stays accountable — and can prove it.
The most sensitive things you give Veela — your ASIC corporate key, your e-signature provider's API key — are envelope-encrypted with AES-256-GCM under a dedicated data-encryption key, separate from the keys that sign sessions. They're decrypted only at the moment of use, never shown back in full, and never logged.
Veela's primary database runs in Sydney. Statutory registers, minute books and company details for Australian companies stay onshore, and everything moves over TLS in transit.
Sign-ins, failed attempts, password changes and 2FA events are recorded to a security log you can review in Settings. Register edits carry a field-level audit trail, and the minute book is append-only — records are added, never silently rewritten.
If you believe you've found a security issue in Veela, tell us before you tell anyone else — reports sent through the contact form are read with priority, and we'll keep you informed as we fix it.