Last updated 25 August 2026
Security is a design constraint in Staffvelo, not a feature. Here is what we do, in plain terms.
Each company has its own workspace at company.staffvelo.com. Every database row carries the company identifier and every query is scoped to it; a workspace can never read another workspace's records. Requests to a subdomain that isn't a workspace are refused rather than falling back to another company.
Strict Content-Security-Policy, output encoding everywhere, parameterised queries throughout, file-type and size limits on uploads. Payment details go straight to Stripe and never touch our servers.
Transactional email is sent via Resend from a domain authenticated with DKIM, SPF and DMARC.
The database keeps point-in-time recovery for 30 days. When a customer asks us to delete a workspace, its data is removed from live systems within 30 days.
Please email security@staffvelo.com. We acknowledge reports within two working days, keep you informed, and don't take action against good-faith research.