How VeLens handles your data
The AI model sees Marketing Cloud metadata: schemas, counts, names, headers and errors. It never sees subscriber rows, contact details or attribute values. Your credentials stay on our server, encrypted at rest, and never reach the browser. Writes are proposed first and run only when someone confirms them. Access runs through your org's own Installed Package, so you can revoke it from SFMC Setup at any moment.
Full detail is in the Privacy Policy and the Terms.
Your package, your control
Access flows through your org's own Installed Package OAuth. You grant it, and you revoke it from SFMC Setup, under Apps then Installed Packages. Revoking cuts off API access immediately.
Credentials never touch the browser
Refresh tokens are held server-side and encrypted at rest. The browser only ever receives a short-lived token scoped to the one business unit you are working in.
Subscriber data stays home
No subscriber rows, contact details or attribute values reach the model. Schemas, counts, headers and errors only. This is structural and enforced on the server, not a setting anyone can toggle off.
Nothing changes without a confirm
Writes propose first. Nothing changes in your org until someone confirms, and what runs is the exact tool that was proposed, with the exact arguments shown.
A full audit trail
Every tool call and every confirmed write is recorded: who asked, what ran, and what changed. Every member can read the trail on the Activity page in the web app. Who asked is shown to owners and admins.
Zero-data-retention AI routing
Model calls run through a gateway with zero data retention enabled, configured to fail closed. If a zero-retention route is not available the request errors out. There is no silent fallback to another provider.
Business-unit scoping
Answers stay inside the business unit you are working in. Every request is checked against the business units your connection is actually allowed to reach.
Roles and feature toggles
Admins decide which capabilities the org can use, and what the AI may read or write. Set it org-wide or per role. Switch a capability off and it disappears for everyone, on every surface.
One capability is a disclosed exception, and it stays off until an org admin turns it on. The AI can check a single subscriber's engagement history, looked up by a key the user types in. It returns email, journey and list names, dates and statuses only, and the identifier itself is masked in everything sent to the model.
What we don't claim
We do not hold a SOC 2 report or an ISO 27001 certificate, and you will not find those badges on this site. What we do claim is specific, checkable, and listed on this page.
If your team needs something we have not covered here, ask us. We will answer plainly, including when the answer is no.
Sub-processors
These are the companies that process data on our behalf. The full table, with exactly what each one receives, is in the Privacy Policy.
| Sub-processor | Purpose |
|---|---|
| Vercel, Inc. | Hosts the VeLens web app and API |
| Supabase, Inc. | Database and authentication, including the encrypted SFMC tokens, conversation history and audit log |
| Cloudflare, Inc. | Stores the daily backups, encrypted before they are sent, with no key held by Cloudflare |
| Salesforce, Inc. | VeLens' own Sales Cloud and Marketing Cloud accounts, holding our customer records and the emails we send you. No data from your tenant, your conversations or your tokens |
| Vercel, Inc. (AI Gateway) | Routes model calls, with zero data retention enabled and configured to fail closed |
| Microsoft Corporation | Azure OpenAI Service, running the model reached through the gateway |
We update this list and give notice through the product or by email before we add or replace a sub-processor.
Questions from your security team
Send them over and we will answer in writing. Vulnerability reports go to security@velens.cloud.
Put an intelligence layer on your org
Install the extension and VeLens shows up inside Marketing Cloud, next to the work you are already doing.