Access is a decision. Not a side effect.
Giving an external team access to customer data, CRM records, or internal systems is a serious decision. Veilancy treats it as a designed control environment: tailored to each client's workflow, documented in the account playbook, and governed by the practices below.
Every client brings a different stack, sensitivity level, and compliance context. Instead of a generic checklist, we design controls around your specific engagement — your tools, data boundaries, access rules, and reporting expectations.
The practices below are the baseline we operate from today. We're also maturing our internal control environment toward recognized assurance frameworks, so our standards can be externally validated as we grow.
Thirteen practices every engagement runs on.
- 01
Role-based access
Team members get access to the systems their role requires and nothing beyond it. Requests go through the account lead, not arranged informally.
- 02
Client-controlled permissions
Accounts are provisioned inside your own tools, under your own administration. You decide what each seat can see, and can change or withdraw it anytime.
- 03
Confidentiality agreements
Team members assigned to a client sign confidentiality terms covering client, customer, and commercial data. Client-specific paper can be used where required.
- 04
Credential practices
We favour individually named accounts over shared credentials wherever your tooling supports them. Where credentials must be issued, they're handled by the account lead and recorded for rotation on exit.
- 05
Multi-factor authentication
MFA is enabled on client systems that support it, per your policy. Where tooling doesn't support MFA, we say so rather than implying protection that isn't there.
- 06
Password management
Team members must use a password manager for work credentials, and never store client passwords in personal notes, browsers, or messaging apps.
- 07
Device requirements
Team members work on machines meeting a documented baseline: current OS, disk encryption, screen lock, and no shared household use of the work profile.
- 08
Offboarding and access revocation
When someone leaves an account or the company, access revocation is a checklist item with a named owner. The client is notified and can verify removal in their own admin console.
- 09
Escalation procedures
Every engagement has a defined escalation path with named contacts on both sides, so a suspected issue reaches a decision-maker fast.
- 10
Client data boundaries
Client data stays inside client systems. Teams are instructed not to export, copy, or move records into personal storage or unapproved tools.
- 11
Process documentation
Handling rules for each engagement are written into the account playbook, so new team members are trained on them rather than inheriting them by habit.
- 12
Incident response
Suspected incidents are reported same-day to the account lead, contained first, then documented: what happened, what was affected, what changed. Clients are told promptly.
- 13
Tooling approval and review
New tools touching client work are approved before use, not adopted quietly. Access lists are reviewed on a set cadence and whenever a role changes.
Checks you can run yourself.
Your admin console is the source of truth
Because seats live in your tools, you can see who has access, at what level, and when it changed — without asking us for a report.
Access changes are announced
Joiners, movers, and leavers on your account are communicated to your named contact, so removal can be confirmed same-day.
Controls are written before work starts
Access rules, data boundaries, escalation contacts, and reporting cadence are agreed in the account playbook during the pilot, not negotiated after an issue.
Your paper, if you prefer it
We'll work to your NDA, security addendum, or vendor questionnaire, and answer plainly — including where a control isn't in place yet.
If you believe there's a security issue involving Veilancy, our website, or an engagement, email contact@veilancy.com with the details. Reports are reviewed by a named owner, and we'll confirm receipt within one business day.
Have a control
we need to meet?
Send it with your pilot request. We'll tell you plainly what we can support today, what we'd need to put in place, and what we can't do.