Skip to content
VELLITAS
Problem Platform Methodology Patents About Contact
Talk to Vellitas

Operational practice

Data & responsible scanning

Effective September 18, 2026

This statement describes the operating baseline Vellitas uses for outside-in assessments. A customer agreement may define a narrower scope, different retention period, or additional controls. This statement is not permission for any person to scan systems they do not own or have authority to assess.

Authorized scope

Vellitas performs customer work under written authorization. Customers provide seed domains, brands, subsidiaries, acquired names, networks, or other scope information. Related assets discovered from public evidence are treated as candidates until Vellitas or the customer confirms that they belong in scope. Candidate association alone is not presented as proof of ownership.

What an assessment observes

A certificate assessment may record the certificate chain, subject and subject alternative names, issuer, serial number, validity, fingerprints, public-key and signature characteristics, TLS protocol and cipher support, chain completeness, compression or renegotiation behavior where relevant, revocation signals, DNS and reverse DNS, IP address, network owner, observed geolocation, service port, observation time, and changes between observations.

Vellitas may derive findings, confidence, severity, ownership candidates, remediation instructions, scripts, verification results, and trend information from that evidence.

Efficient, low-impact collection

Vellitas uses rate-limited connections and the minimum protocol exchange needed to observe the relevant public evidence. A typical certificate check establishes a TLS handshake, records the required metadata, and closes the connection. Retries use backoff, concurrency is bounded, and scanning pauses when a service indicates stress. The certificate assessment does not download or index application page content.

What Vellitas does not access

The standard outside-in assessment does not use customer credentials, access private keys, sign in to user accounts, query application databases, decrypt user payloads, enter internal networks, exploit a vulnerability, guess passwords, evade an access control, or perform denial-of-service or other availability testing. Any separately authorized test must be documented with its own scope and safeguards.

Standard retention schedule

Vellitas stores only what is reasonably necessary to deliver the service, preserve a defensible historical view, verify remediation, meet legal obligations, and protect the service. The following schedule is the default unless a customer agreement requires a shorter or longer period:

Certificate, TLS, DNS, network, geospatial, and derived historical observations
For the subscription term and up to seven years afterward
Findings, reports, remediation plans, approved scripts, verification evidence, and audit history
For the subscription term and up to seven years afterward
Candidate asset associations not approved into customer scope
Up to 90 days
Website contact requests
Up to 24 months after the last substantive interaction
Routine web and security logs
30 days; relevant records may be preserved for up to one year during a security investigation
Backups containing deleted information
Expire through the normal backup cycle within 35 days
Contracts, billing, and required corporate records
As required by law, generally seven years

At the end of the applicable period, records are deleted or irreversibly aggregated. Vellitas may preserve specific records when required by law, a litigation hold, fraud prevention, or an active security investigation. Customers may contract for a different retention period where operationally and legally feasible.

Separation and access

Customer scope, observations, findings, reports, and remediation artifacts are assigned to that customer. Any future customer portal will enforce tenant scope at the data layer, use role-based access, maintain audit records, and prevent a search from returning assets outside the customer's approved portfolio.

Questions or scanning concerns

A system owner who believes a Vellitas observation is causing harm, is misattributed, or should be paused can use the contact form. Include the affected hostname or IP address, the relevant time, and a way for Vellitas to verify the requester's authority. Vellitas will investigate and can suppress or rate-adjust an endpoint while the concern is reviewed.

VELLITAS
Platform Methodology Contact Privacy Data & scanning

© 2026 Vellitas, LLC · Wyoming