Skip to main content
Security at vly works at three layers: the platform (vly’s infrastructure), the runtime (how your app handles data), and the practice (the workflows your team follows). This page is the executive overview; the rest of this section deep-dives each topic.

What vly does for you

Encryption at rest and in transit

All data in Convex’s managed database is encrypted at rest with AES-256. All API and admin traffic uses TLS 1.3.

Secrets isolation

API keys and other secrets live in vly’s secrets store, scoped per environment, never exposed to client code. See Secrets management.

Per-tenant isolation

Each workspace’s data is logically isolated. The Convex query layer prevents cross-tenant reads.

Audit logs

Every meaningful action — sign-in, settings change, API call — is logged. Available for export.

DDoS protection

Edge-level rate limiting and DDoS mitigation on every vly-served endpoint.

Backups

Convex maintains continuous backups; point-in-time restore available on Business+ tiers.

What your app should do

The platform handles infrastructure security. Application-level security — input validation, access control, secrets handling in your custom code — is yours.

Validate input at the boundary

Convex schema validators catch most bad data; for business rules, validate inside mutations.

Scope every query to the user

Use ctx.auth.getUserIdentity() and filter on the user’s workspace / team. The default vly-generated code does this; preserve it.

Never expose secrets to the client

Anything in process.env is server-only. Anything starting with VITE_ is client-visible — only public keys belong there.

Rate limit user-facing actions

Login attempts, sign-up, password reset, API endpoints exposed to the public — all need rate limits.

Sanitize and escape

React handles most XSS by default. For raw HTML or user-generated markdown, use a sanitizer. CSRF is handled by built-in auth.

Audit-log meaningful actions

Beyond vly’s platform audit log, your app should log domain-meaningful actions (sent invoice, deleted account, ran agent on production).

Threat model

The threats vly’s platform defends against: For application-level threats (XSS, CSRF, SQLi-equivalent in Convex, IDOR), see the linked deep-dives below.

Compliance

GDPR

Customer data export and deletion supported via Data export and Account deletion. DPA available on request.

SOC 2 Type II

Audit in progress; report available to Enterprise customers. Email security@vly.ai for status.

HIPAA

Not currently supported. If you need HIPAA, contact enterprise@vly.ai about timing.

ISO 27001

Roadmap.

Reporting a security issue

If you’ve found a security vulnerability:
  1. Do not file a public issue or post on social media.
  2. Email security@vly.ai with details.
  3. We’ll acknowledge within 24 hours and work with you on disclosure timing.
We follow coordinated disclosure. Researchers acting in good faith are eligible for our bug bounty program — email for details.

Security checklist for production apps

Before launching a vly app to real users:
  • All third-party API keys live in vly’s secrets store (not in code, not in VITE_*).
  • All Convex queries scope by ctx.auth.getUserIdentity().
  • All Convex mutations validate input via the schema validators (v.string(), v.number(), etc.).
  • User input rendered as raw HTML is sanitized (use DOMPurify or similar).
  • Login, signup, and password-reset endpoints are rate-limited.
  • Account deletion is tested end-to-end.
  • Webhook handlers verify signatures (Stripe, Resend, etc. — every integration that pushes events).
  • Audit log is reviewed before launch (no surprising actions).
  • DNS for the custom domain has a current SPF / DKIM / DMARC config (for email deliverability and anti-spoofing).
  • Privacy policy and terms of service are linked from the app.

Deep dives

Auth best practices

Patterns for sign-up, password reset, MFA, session management.

Secrets management

The secrets store: encryption, scoping, rotation, audit.

Input validation

Schema validators, business rule validation, sanitization.

Data access control

Per-user, per-workspace, per-team scoping patterns.

XSS / CSRF

React defaults, edge cases, when to sanitize, CSRF model.

Rate limiting

Per-IP, per-user, per-endpoint patterns.

Audit logs

What’s logged, where to read it, how to export.

Compliance

GDPR, SOC 2, DPAs, sub-processors.

Data export

Self-service export for users and admins.

Account deletion

Permanent deletion, what’s retained, what’s purged.
Last modified on April 18, 2026