Operational practice
Data & responsible scanning
Effective September 18, 2026
This statement describes the operating baseline Vellitas uses for outside-in assessments. A customer agreement may define a narrower scope, different retention period, or additional controls. This statement is not permission for any person to scan systems they do not own or have authority to assess.
Authorized scope
Vellitas performs customer work under written authorization. Customers provide seed domains, brands, subsidiaries, acquired names, networks, or other scope information. Related assets discovered from public evidence are treated as candidates until Vellitas or the customer confirms that they belong in scope. Candidate association alone is not presented as proof of ownership.
What an assessment observes
A certificate assessment may record the certificate chain, subject and subject alternative names, issuer, serial number, validity, fingerprints, public-key and signature characteristics, TLS protocol and cipher support, chain completeness, compression or renegotiation behavior where relevant, revocation signals, DNS and reverse DNS, IP address, network owner, observed geolocation, service port, observation time, and changes between observations.
Vellitas may derive findings, confidence, severity, ownership candidates, remediation instructions, scripts, verification results, and trend information from that evidence.
Efficient, low-impact collection
Vellitas uses rate-limited connections and the minimum protocol exchange needed to observe the relevant public evidence. A typical certificate check establishes a TLS handshake, records the required metadata, and closes the connection. Retries use backoff, concurrency is bounded, and scanning pauses when a service indicates stress. The certificate assessment does not download or index application page content.
What Vellitas does not access
The standard outside-in assessment does not use customer credentials, access private keys, sign in to user accounts, query application databases, decrypt user payloads, enter internal networks, exploit a vulnerability, guess passwords, evade an access control, or perform denial-of-service or other availability testing. Any separately authorized test must be documented with its own scope and safeguards.
Standard retention schedule
Vellitas stores only what is reasonably necessary to deliver the service, preserve a defensible historical view, verify remediation, meet legal obligations, and protect the service. The following schedule is the default unless a customer agreement requires a shorter or longer period:
- Certificate, TLS, DNS, network, geospatial, and derived historical observations
- For the subscription term and up to seven years afterward
- Findings, reports, remediation plans, approved scripts, verification evidence, and audit history
- For the subscription term and up to seven years afterward
- Candidate asset associations not approved into customer scope
- Up to 90 days
- Website contact requests
- Up to 24 months after the last substantive interaction
- Routine web and security logs
- 30 days; relevant records may be preserved for up to one year during a security investigation
- Backups containing deleted information
- Expire through the normal backup cycle within 35 days
- Contracts, billing, and required corporate records
- As required by law, generally seven years
At the end of the applicable period, records are deleted or irreversibly aggregated. Vellitas may preserve specific records when required by law, a litigation hold, fraud prevention, or an active security investigation. Customers may contract for a different retention period where operationally and legally feasible.
Separation and access
Customer scope, observations, findings, reports, and remediation artifacts are assigned to that customer. Any future customer portal will enforce tenant scope at the data layer, use role-based access, maintain audit records, and prevent a search from returning assets outside the customer's approved portfolio.
Questions or scanning concerns
A system owner who believes a Vellitas observation is causing harm, is misattributed, or should be paused can use the contact form. Include the affected hostname or IP address, the relevant time, and a way for Vellitas to verify the requester's authority. Vellitas will investigate and can suppress or rate-adjust an endpoint while the concern is reviewed.