Veyla · Security
Security.
Last updated 8 August 2026
Veyla sits on the physical door of your facility and, for members who opt in, holds the most personal credential there is. That position earns scrutiny — this page is the standing answer. It covers how biometric data is guarded, how the platform is engineered, and where we are honestly at on certification.
Biometrics: the question behind every other question
They never touch your management system — Face enrolment, consent, storage and deletion are entirely Veyla’s. Your membership platform never sees a photo or a template — which keeps your systems, and your vendors’, clean of special-category data.
Consent is its own step — Express opt-in, recorded, never bundled into T&Cs. The selfie is captured on the member’s own phone. A member who declines is a fully supported first-class state — a fob or PIN works just as well, at no detriment. There is no passive scanning: capture is trigger-based at the reader only.
Storage is Australian and encrypted — The canonical photo lives encrypted in-region. Reader templates are derived, disposable caches — instantly revocable, regenerable, never the source of truth.
Deletion is automated, not promised — Consent withdrawal destroys the photo and every template immediately. Membership cancellation destroys them automatically after a short grace window. Both paths purge every reader the template ever reached and leave a full audit trail.
Platform and integration security
Encryption and credentials — TLS everywhere; webhook signature verification; scoped, per-club API credentials on integrations — members read, webhooks, check-in write, nothing else.
Hard tenant isolation — Every facility’s data is separated by database row-level security — isolation is enforced by the database engine itself, not by application code remembering to filter. Encryption at rest across the platform.
Outbound-only devices — Every device connection is outbound from the club — no inbound ports, no port-forwarding, nothing listening on your network. A Veyla box on your LAN is a client, never a server.
Offline-safe doors — Door decisions are made locally on the hardware. An internet outage never locks paying members out and never lets lapsed members in.
Data minimisation by design — Integrations request the minimum fields needed to run doors and alerts — no billing data, no payment methods, no documents. What we don’t hold can’t leak.
Pro-grade hardware lineage — Door control builds on the HID ecosystem with secure-side relay options — the unit on the wall is not the enforcement point, so ripping a reader off the wall opens nothing.
Where we are on certification — the honest line
SOC 2 and ISO 27001 certification are not yet held — Veyla is a new platform, and we won’t claim badges we haven’t earned. The architecture is built to that standard, and an independent penetration test and a certification roadmap are committed steps in formalising any chain rollout. If you’re evaluating Veyla for a multi-site deployment, we’ll walk your security team through the architecture directly.
Reporting a vulnerability
If you believe you’ve found a security issue in Veyla, tell us at dev@veyla.com.au and include enough detail to reproduce it. We respond to genuine reports quickly, we won’t take action against good-faith research, and we’ll credit you if you’d like us to.