Security

Enterprise-grade security built in from the start

Velixa protects your data and your clients' data with layered, serious-business security — not tick-box theatre. PCI-compliant, GDPR-aware and hardened against common attacks by default.

Included in every Velixa subscription

What you get

  • Encryption in transit and at rest — TLS everywhere, sensitive data encrypted at rest.
  • CSRF protection on every form — Every state-changing request is verified — no cross-site request forgery.
  • Rate limiting and bot controls — Public booking and login endpoints are rate-limited and bot-protected.
  • PCI-compliant card processing — Stripe handles all card data — Velixa servers never see card numbers.
  • GDPR data exports and deletion — Export or delete any customer's data in seconds from the dashboard.
  • Role-based access and audit logs — Every sensitive action is logged with who, what and when.
Encrypted & protected
TLS 1.3 in transit
AES-256 at rest
PCI DSS via Stripe
GDPR data tools
2FA & rotating sessions
CSRF + rate limits

How it fits into your day

PCI-SCC certified checkout

Card tokenisation and 3D Secure handled entirely within Stripe's certified environment.

Per-customer consent records

Marketing consent is captured with timestamp, IP and source — full audit trail.

Transparent incident policy

Any breach affecting your data triggers notification within 72 hours as required by UK GDPR.

Common questions

All data is stored on servers in the United Kingdom and European Economic Area. We do not transfer data to third countries outside the UK/EEA.

Yes — Velixa is registered with the Information Commissioner's Office (ICO) as a data controller.

From any customer profile, use the "Export data" and "Delete customer" actions. Both comply with Subject Access Request and right-to-erasure obligations.

Ready to switch on?

Every feature is yours from day one of your free trial — no contracts, cancel any time.

Start 7-day free trial