What vly does for you
Encryption at rest and in transit
All data in Convex’s managed database is encrypted at rest with AES-256. All API and admin traffic uses TLS 1.3.
Secrets isolation
API keys and other secrets live in vly’s secrets store, scoped per environment, never exposed to client code. See Secrets management.
Per-tenant isolation
Each workspace’s data is logically isolated. The Convex query layer prevents cross-tenant reads.
Audit logs
Every meaningful action — sign-in, settings change, API call — is logged. Available for export.
DDoS protection
Edge-level rate limiting and DDoS mitigation on every vly-served endpoint.
Backups
Convex maintains continuous backups; point-in-time restore available on Business+ tiers.
What your app should do
The platform handles infrastructure security. Application-level security — input validation, access control, secrets handling in your custom code — is yours.Validate input at the boundary
Convex schema validators catch most bad data; for business rules, validate inside mutations.
Scope every query to the user
Use
ctx.auth.getUserIdentity() and filter on the user’s workspace / team. The default vly-generated code does this; preserve it.Never expose secrets to the client
Anything in
process.env is server-only. Anything starting with VITE_ is client-visible — only public keys belong there.Rate limit user-facing actions
Login attempts, sign-up, password reset, API endpoints exposed to the public — all need rate limits.
Sanitize and escape
React handles most XSS by default. For raw HTML or user-generated markdown, use a sanitizer. CSRF is handled by built-in auth.
Audit-log meaningful actions
Beyond vly’s platform audit log, your app should log domain-meaningful actions (sent invoice, deleted account, ran agent on production).
Threat model
The threats vly’s platform defends against:
For application-level threats (XSS, CSRF, SQLi-equivalent in Convex, IDOR), see the linked deep-dives below.
Compliance
GDPR
Customer data export and deletion supported via Data export and Account deletion. DPA available on request.
SOC 2 Type II
Audit in progress; report available to Enterprise customers. Email security@vly.ai for status.
HIPAA
Not currently supported. If you need HIPAA, contact enterprise@vly.ai about timing.
ISO 27001
Roadmap.
Reporting a security issue
If you’ve found a security vulnerability:- Do not file a public issue or post on social media.
- Email security@vly.ai with details.
- We’ll acknowledge within 24 hours and work with you on disclosure timing.
Security checklist for production apps
Before launching a vly app to real users:- All third-party API keys live in vly’s secrets store (not in code, not in
VITE_*). - All Convex queries scope by
ctx.auth.getUserIdentity(). - All Convex mutations validate input via the schema validators (
v.string(),v.number(), etc.). - User input rendered as raw HTML is sanitized (use DOMPurify or similar).
- Login, signup, and password-reset endpoints are rate-limited.
- Account deletion is tested end-to-end.
- Webhook handlers verify signatures (Stripe, Resend, etc. — every integration that pushes events).
- Audit log is reviewed before launch (no surprising actions).
- DNS for the custom domain has a current SPF / DKIM / DMARC config (for email deliverability and anti-spoofing).
- Privacy policy and terms of service are linked from the app.
Deep dives
Auth best practices
Patterns for sign-up, password reset, MFA, session management.
Secrets management
The secrets store: encryption, scoping, rotation, audit.
Input validation
Schema validators, business rule validation, sanitization.
Data access control
Per-user, per-workspace, per-team scoping patterns.
XSS / CSRF
React defaults, edge cases, when to sanitize, CSRF model.
Rate limiting
Per-IP, per-user, per-endpoint patterns.
Audit logs
What’s logged, where to read it, how to export.
Compliance
GDPR, SOC 2, DPAs, sub-processors.
Data export
Self-service export for users and admins.
Account deletion
Permanent deletion, what’s retained, what’s purged.
