How we protect your data
Last updated: July 2026
This page is maintained by Slingshot, Inc. to describe the security practices behind Veyo. It reflects controls we have enabled today. It is not an independent certification or audit.
Shared responsibility
Security is a partnership. Slingshot secures the Veyo platform and infrastructure. Educators, schools, and districts are responsible for protecting their account credentials, managing who has access at their institution, and following their district's policies for classroom use.
All traffic to helloveyo.com and app.helloveyo.com is served over HTTPS with modern TLS.
Veyo runs on reputable managed cloud providers with encryption at rest for stored data.
Educator accounts require sign-in. Access to lessons and content is scoped to the account that created them.
Only a limited number of Slingshot personnel can access production systems, and only when required to operate the service.
Data handling
- Content you create in Veyo is stored under your educator account.
- We do not sell personal information and do not use your content to train third-party AI models.
- Backups are performed on a routine schedule and stored securely.
- A list of the subprocessors that support Veyo (hosting, database, email, AI models, analytics) is available on request.
Account and access safeguards
- Passwords are hashed; Slingshot staff never see them in plaintext.
- Sessions expire and can be revoked by signing out.
- Administrative access to production is limited and logged.
Incident response
If we become aware of a security incident that affects your account or data, we will investigate promptly and notify affected account holders in line with applicable law. Suspect an incident? Email security@helloveyo.com right away.
Reporting a vulnerability
If you believe you've found a security vulnerability in Veyo, please report it to security@helloveyo.com with steps to reproduce. We ask researchers to give us reasonable time to investigate and remediate before public disclosure and to avoid accessing accounts or data that aren't their own.
Compliance posture
Veyo aligns its practices with recognized student-privacy expectations such as FERPA and COPPA, where the responsible educator or institution obtains the required consents. Slingshot does not currently make third-party certification claims (SOC 2, ISO 27001, etc.) on this page. If your district requires a formal security review, contact us and we'll share the documentation we have available.