Enterprise-grade security built in from the start
Velixa protects your data and your clients' data with layered, serious-business security — not tick-box theatre. PCI-compliant, GDPR-aware and hardened against common attacks by default.
What you get
- Encryption in transit and at rest — TLS everywhere, sensitive data encrypted at rest.
- CSRF protection on every form — Every state-changing request is verified — no cross-site request forgery.
- Rate limiting and bot controls — Public booking and login endpoints are rate-limited and bot-protected.
- PCI-compliant card processing — Stripe handles all card data — Velixa servers never see card numbers.
- GDPR data exports and deletion — Export or delete any customer's data in seconds from the dashboard.
- Role-based access and audit logs — Every sensitive action is logged with who, what and when.
How it fits into your day
PCI-SCC certified checkout
Card tokenisation and 3D Secure handled entirely within Stripe's certified environment.
Per-customer consent records
Marketing consent is captured with timestamp, IP and source — full audit trail.
Transparent incident policy
Any breach affecting your data triggers notification within 72 hours as required by UK GDPR.
Common questions
All data is stored on servers in the United Kingdom and European Economic Area. We do not transfer data to third countries outside the UK/EEA.
Yes — Velixa is registered with the Information Commissioner's Office (ICO) as a data controller.
From any customer profile, use the "Export data" and "Delete customer" actions. Both comply with Subject Access Request and right-to-erasure obligations.
Ready to switch on?
Every feature is yours from day one of your free trial — no contracts, cancel any time.
Start 7-day free trial