Always on · Security

Entry event · #482917:42 AM
DoorFront · The AldenAUDIT LOGGED
Authorized byResident · Unit 3CATTRIBUTABLE
Resident emailaes256:v3:9f4a…e21cENCRYPTED
Search indexhmac:blind:77d0…NO PLAINTEXT
AUDIT WRITE CONFIRMED ✓ · SENSITIVE READS FAIL CLOSED

Locked by default, answerable always.

Veni was built assuming a board, a regulator, or a resident will one day ask exactly what happened and who saw it. Every field above is real behavior, not a badge.

If the database leaks · At rest

A stolen copy reads as noise.

Names, emails, phones, notes, and call transcripts are encrypted with AES-256-GCM before they reach the database, under keys the database never holds.

  • Keys that rotate. Encryption keys are versioned, held outside the data they lock, and retire on a current-plus-previous rotation path.
  • Search without plaintext. Staff lookups match a blind index, a one-way fingerprint, so the database never keeps a searchable readable copy of contact info.
  • Private media. Sensitive files live in private storage and are served only through an authenticated, audit-logged proxy. No public URLs.
What a stolen backup holdsusers · row 8,412
email_encaes256:v3:9f4a2c81…e21c
phone_encaes256:v3:b81f77d4…03aa
email_bidxhmac:77d0c4a9f2…
NOTHING READABLE
The same row · in the portalRole-checked · Audit-logged
ResidentDana R. · Unit 4BDECRYPTED IN-APP

Break-glass · Every look logged

No look without a record of the look.

Access is role-gated and scoped to the buildings a person manages. And for the most sensitive records, the audit isn't best-effort, it's the precondition.

  • Fail-closed reads. Opening a signed document or revealing the identity behind a de-identified record is denied outright if the audit entry can't be written.
  • A stated basis. Board investigations are time-boxed and carry a written reason for the record.
  • Disclosure on your terms. Residents are notified under the policy your building chooses.
Break-glass · Reveal identityActivity #52108
Resident · Unit ██Reveal

audit ✓  reveal · j.alvarez (manager) · basis: package dispute · 9:14 AM

Dana R. · Unit 4B
Resident · Unit ██Reveal

audit ✗  write failed · 9:16 AM

READ DENIED · RECORD STAYS SEALED

At the desk · Verdict, not document

The ID check that keeps no ID.

When the front desk checks a visitor's ID, the barcode is verified on the device. What's kept is the name, encrypted, and the result. Never a picture of the ID.

  • No image, by architecture. There is no photo to leak, because none is stored.
  • Retention with an end. ID-check records live under a 30, 60, or 90-day window your building sets.
  • Deletion, confirmed. Purges are verified complete, not assumed. No silent orphans.
ID check · Front deskVerified on-device
ResultMatchVERIFIED ✓
Nameaes256:v3:44c1a9…9e0bENCRYPTED
PhotoNo image · never captured
Retention · 30 daysDELETION CONFIRMED ✓

Residents · Visibility is policy

Staff see their job, not your life.

The front desk never receives a resident's email address. That's enforced at the API and tested in CI, not a screen that politely hides a field.

  • Three visibility modes. The activity log renders identified, pseudonymous, or aggregate, set per building as policy.
  • Neighbors stay neighbors. Direct messages between residents never appear on a staff surface.
  • Tokens in the vault. On phones and tablets, sign-in tokens live in the platform keychain, never in plain app storage.
Front desk tablet · Resident card
Unit4B
NameDana R.
Emailnever sent to the deskAPI-ENFORCED
Activity log · VisibilitySet per building
IdentifiedDana R. · 4B · Front door · 7:42 AM
PseudonymousResident · Unit 4B · Front door · 7:42 AM
Aggregate14 entries today · all authorized

And the rest

The small print, in plain sight.

Encrypted at rest

Names, emails, phones, and call transcripts are AES-256 encrypted with versioned, rotatable keys.

Searchable without plaintext

Staff lookups run on blind indexes. The database never holds a searchable plaintext copy of contact info.

Fail-closed auditing

Access to the most sensitive data is denied outright if the audit write fails. No read without a record of the read.

Retention, then deletion

Sensitive media and ID-check records live under 30, 60, or 90-day windows, then purged with deletion confirmed. An ID check keeps only a match result, never a picture of the ID.

AI on your terms

Veni Intelligence is opt-in per building with monthly budgets. Transcripts it reads are encrypted like everything else.

Transparent governance

Board investigations are time-boxed with a stated basis, and residents are notified under the disclosure policy you choose.

IN TRANSIT: TLS everywhere · HSTS on web apps · webhook signatures verified · secrets compared in constant time

Due diligence · Get started

Bring your board's questions.

A demo takes twenty minutes. Ask about encryption, audits, retention, or whatever your building's counsel wants answered, and watch the answers on a live screen instead of a slide.

Get a demoOr read the privacy policy →