Public-site safeguards
- Server-side input validation and bounded request sizes.
- Security headers and a restrictive content policy.
- Secrets kept in deployment environment bindings—not browser code or source control.
- Abuse controls for public forms and support conversations.
- A separate public site boundary from the authenticated operational platform.
Responsible disclosure
If you believe you found a security issue, do not access or alter information that is not yours. Send a clear report to security@velohub.ai. Include the affected URL, reproduction steps, impact, and any supporting screenshots. Do not include credentials or real customer data.