Security

Security should be inspectable, not decorative.

Veilleur.studio handles customer communications and workflow data. That means this page describes real controls and real responsibilities — not a wall of badges the product has not earned. It is updated whenever the production architecture or subprocessors change.

Security data flow across bounded components with access-control gates.

Know where information moves

A typical configured workflow can involve inbound telephony or another connected channel, AI conversation processing, Veilleur.studio workflow/backend processing, logging and telemetry, the configured CRM or destination system, and human handoff or notification. A deployment documents which systems are active for that customer rather than imply every possible component is always used.

Limit access to the people and systems that need it

Production access is role-based and reviewed. Administrative access, customer credentials and operational tools are separated according to least-privilege principles. Exact controls are published only after they are implemented and documented.

Credentials and secrets never live in page code or shared documents

Integration secrets are stored in an appropriate secret-management mechanism, restricted to the services that require them and rotated when compromise is suspected or policy requires it.

Operational events should leave evidence

The system retains sufficient event history to investigate failed transfers, CRM writes, fallback events, configuration changes and other material workflow behavior, subject to the customer’s retention configuration and privacy requirements.

Keep data because the workflow requires it — not because storage is cheap

Customer deployments have documented retention and deletion rules for transcripts, recordings, structured lead data, logs and backups where applicable. Exact retention periods reflect the implemented service and customer agreement.

Security incidents need a defined response path

The operating procedure defines how Veilleur.studio identifies, contains, investigates and communicates relevant incidents, including which customer contacts receive notices when required.

See the services involved in delivering the product

Veilleur.studio maintains an up-to-date subprocessor list that identifies the relevant provider, purpose and applicable data-processing role.

Role-based least-privilege access around the real estate AI workflow.

Certifications

Veilleur.studio does not display SOC 2, ISO 27001 or other certification badges unless it has actually obtained the stated certification and can substantiate its scope. A subprocessor’s certification does not automatically make Veilleur.studio certified.

Have a security question before your demo?

Send the requirement or security-questionnaire item that matters to your brokerage. We would rather answer a specific control question than hide behind a generic “enterprise-grade” claim.