Security

Security and trust

Veesie shows how AI assistants like ChatGPT, Gemini and Perplexity talk about your brand. To do that you trust Veesie with your brand data, and sometimes your Google Analytics. This page explains exactly how Veesie protects that data: encrypted, in the EU, and accessible only to you.

Always encrypted

Sensitive fields, like your Google tokens, are encrypted with AES-256-GCM. All connections run over HTTPS with HSTS.

EU hosting

Your account, brands and results are stored in a PostgreSQL database in Frankfurt. To measure, your questions also pass through services in the US; which ones is listed further down this page.

Read-only AI access

The Google Analytics connection is read-only. Veesie can never change or delete your statistics.

Strict isolation

Each customer sees only their own data, enforced twice: at database level (RLS) and in the application.

1. Your data and AI monitoring

To measure how AI sees your brand, Veesie sends your prompts (questions about your brand, your sector and your competitors) to AI providers like OpenAI, Anthropic, Google and Perplexity. We store their answers in our EU database.

Tip: don't put personal data in your prompts yourself. It isn't needed for brand monitoring, and it keeps the processed data minimal.

2. Encryption

In transit

All traffic to veesie.com runs over HTTPS. We send a Strict-Transport-Security header (HSTS) with a two-year duration and are on the HSTS preload list, so browsers never connect unencrypted.

At rest

Sensitive fields in our database, like your Google Analytics access and refresh tokens and any webhook URLs, are encrypted with AES-256-GCM (authenticated encryption). If the encrypted data is tampered with, decryption fails automatically. The key is stored separately from the database as a Cloudflare Worker secret.

3. The Google Analytics connection

Many customers connect their Google Analytics 4 to Veesie to see traffic data alongside their AI visibility. That connection is deliberately minimal:

4. Access and authentication

5. Infrastructure and isolation

6. Application security

Veesie is continuously reviewed for security internally. The codebase went through several security audits against the OWASP guidelines for APIs and for LLM applications. Concrete measures include:

No service can guarantee absolute security, but we work continuously to reduce risks and improve our measures.

7. Payments

Payments run via Stripe Checkout. Your card details go directly to Stripe, a PCI-DSS-certified payment provider. Veesie never sees or stores your card details; we only keep a reference to your Stripe customer.

8. Subprocessors

To deliver the service we work with a limited number of carefully chosen subprocessors:

SubprocessorFunctionLocation
Supabase (Postgres + Auth)Database, authenticationEU (Frankfurt)
Cloudflare (Workers)Application hosting, edge processingGlobal network: a request runs through the data centre closest to the visitor, which for European visitors is normally in Europe. Cloudflare, Inc. (US), based on SCCs
ResendTransactional email (notifications, reports)EU region
StripePayment processing (only on a paid plan)Ireland (EU)
SentryError monitoring (error tracking)EU (Frankfurt, Germany)
OpenAI, Anthropic, Google, PerplexityLLM calls (prompts are sent to the providers)US / EU (depending on the provider), based on SCCs
DataForSEOMeasuring Google AI Overviews (your questions are sent to Google as a search query)EU (Estonia), with sub-processors partly in the US, based on SCCs
InngestRunning the measurements (queue, retries and the intermediate results of each step)US (Inngest Inc, AWS servers in the US)

The core data (account, brands, results) is stored in the EU. During a measurement, your questions, your brand name and website, the names of your competitors and the generated recommendations also pass through Inngest in the US, which runs the measurements. Transfers to the AI providers outside the EU happen on the basis of the Standard Contractual Clauses (SCCs). The full list and explanation are in the privacy policy.

9. GDPR and your rights

The data controller for Veesie is Manon BV (trading as ClickForest), based in Bonheiden, Belgium, company number BE 0549.803.522.

10. Reporting a vulnerability

Think you found a security issue? Let us know at hello@veesie.com. We investigate every report and keep you informed. We ask you not to disclose vulnerabilities publicly before we've been able to resolve them together (responsible disclosure).

Last updated: 11 September 2026. Back to veesie.com