§ Documentation

Everything we have,
linked.

Public-facing documentation for Velora Billing. Engineering-internal files (HITRUST.md, ARCHITECTURE.md, RUNBOOK.md, BILLING_ROADMAP.md) live in the source repo and are sent under NDA on request.

API reference
/docs/api
For Engineers integrating velora-billing into a HRIS or data warehouse

REST endpoints, auth, rate limits, pagination, error shapes, webhook events + signature verification, Slack/Teams native webhook support.

Trust + security
/trust
For Buyer + procurement security teams

HITRUST readiness, SOC 2 plan, BAA process, controls list, honest gap list. Every claim links to in-repo evidence.

Subprocessors
/subprocessors
For Procurement, privacy officers

Full vendor list with purpose, region, PHI status (Yes / Conditional / No), BAA status. Updated when subprocessors change.

Privacy policy
/privacy
For Privacy officers, end-customer compliance

What PHI we touch, how it's protected, what we explicitly do NOT do. Authoritative DPA on request.

Data Processing Addendum
/dpa
For Procurement + legal

Roles, subprocessor change notice, breach notification cadence (72h HIPAA + GDPR-aligned), SCCs.

Terms of service
/terms
For Buyers reviewing the MSA package

Overview only — the controlling document is the executed MSA + BAA, sent on request.

Changelog
/changelog
For Existing customers + integrators

Customer-visible release notes. Engineering-internal log lives in the repo.

Security disclosure (RFC 9116)
/.well-known/security.txt
For Researchers + buyer security teams

Machine-readable disclosure entry-point. 90-day SLA on confirmed issues.

Not listed?

Email hello@hellovelora.com. Procurement questionnaires (CAIQ, SIG, HECVAT) and the full DPA + BAA + MSA package are sent within 5 business days under NDA. Security researchers email security@hellovelora.com — 90-day SLA, see /SECURITY.md.