Enterprise and security
Vraelis runs your AI-built apps like production before they ship. Enterprise teams govern who can connect apps and launch runs, verify organization domains, and keep audit-ready records of every run and decision. It is production infrastructure, not a dashboard.
What Vraelis protects
Preflight runs go through a governed pipeline with an audit trail, not an open box anyone can trigger against anything.
Every connected app carries an explicit owner and an I own or authorized this confirmation before a run can touch it.
Organizations sit above workspaces with roles, admins, and membership governance, so access maps to who should have it.
Invite someone as a read-only client viewer, scoped to reports rather than settings, costs, or raw evidence. Sharing a report by public link, with no account, is not built yet.
OIDC single sign-on and verified-domain provisioning bind access to identities your organization already controls.
Billing admins manage payment without owning data or members. Ownership transfer is a deliberate, guarded action.
Member, domain, SSO, billing-admin, ownership, and confirmation-round changes are recorded as a safe, reviewable trail.
Governance controls
The access and identity controls a team can use to run preflight responsibly across an organization.
Auditability
Workspace and organization activity are recorded as a read-only audit trail. Owners and admins review recent governance events in-app at Activity, and can export sanitized governance activity as CSV or JSON. Scheduled exports and retention controls are planned.
Vraelis records key governance events: organization changes, domain verification and re-verification, SSO provider changes, billing-admin changes, confirmation rounds, ownership transfers, and team-access updates. Audit events carry only safe fields: no secrets, no invite or DNS tokens, no token hashes, no Stripe identifiers, no API keys, no OIDC codes or SAML assertions, no certificate bodies, no full URLs, and no IP or device data.
Data handling
Event metadata is whitelisted to safe fields. Emails, tokens, hashes, and Stripe ids are filtered out before anything is recorded or shown.
An organization's OIDC client secret is encrypted at rest (AES-256-GCM) and never returned to the client or logged.
Domain verification stores only the SHA-256 of the DNS TXT token. The raw token is shown once and never persisted.
Screenshots and traces live in a private bucket. No public URL is ever produced, and reads go through short-lived, owner-authorized signed URLs.
Point runs at a preview or staging deployment and keep Stripe in test mode. Vraelis drives the app from the outside, so a run can touch whatever that environment touches.
Card data is processed securely by Stripe. Vraelis never sees card numbers. Your billing overview stays in Vraelis.
We describe what Vraelis actually does. We do not claim formal certifications. If your organization needs specific compliance attestations, contact us to discuss requirements.
SSO and provisioning
Organizations can configure OIDC single sign-on for any verified domain. The id_token is validated (signature, issuer, audience, nonce) and the email domain must match the verified org domain.
SAML configuration is a scaffold today. The SP metadata endpoint exists, but assertion sign-in is not enabled yet, and we will not pretend it is.
Automated provisioning and deprovisioning (SCIM) is planned for larger organizations, not live today.
A verified-domain match maps a user into the organization at a safe role per your settings. It never grants workspace, project, billing, or API access by itself.
Plans
The front door is a free run. These recurring plans are for teams that verify continuously, priced by the run in monthly verifications. Some tiers are still rolling out, so talk to us and we will set you up.
For organizations that need governance, SSO, and audit across many teams. Unlimited runs, Organization governance and audit export, OIDC SSO and verified domains, Client viewer access and billing admins.
For the avoidance of doubt