
Velt
Velt is an embeddable SDK that adds review and approval to software products: contextual comments, staged sign-off, AI review agents, memory and immutable audit trails, so agents propose changes and humans decide before anything ships.
What is Velt?
Velt is an embeddable SDK that adds a review-and-approval layer to someone else's product rather than acting as a standalone application. Its pitch is to add a pull request to your product: agents and people produce work, and nothing changes until a human approves it. The loop runs in three steps. An agent proposes, attaching a confidence score and a rationale to a comment. A human approves or rejects. On approval, the change fires through the customer's own webhook, leaving a permanent record of who allowed what and when. Agents therefore never need write access to customer data.
Seven primitives cover the review side: comments, suggestions, approval flows, audit trail, notifications, memory and review agents. Three of them, namely approval flows, suggestions and memory, are still marked beta. The real-time collaboration layer ships in the same SDK and the same contract: presence with live cursors, selection and follow mode, CRDT multiplayer editing with a single-editor mode and live state sync, voice, video and screen recording with a built-in video editor, and in-document audio and video huddles.
Everything is delivered as React, Next.js, Angular, Vue or plain HTML components plus a typed SDK. Setup means installing the package, wrapping the application in a provider component and dropping in the pieces you want; an official MCP server lets a coding agent in Cursor, Claude Code, Windsurf, Copilot or Zed do that provisioning instead. Around the SDK sit an admin console, developer tools including a Chrome extension and a live debugger, webhooks, REST APIs, more than fifteen first-party integrations and over twenty editor, grid, chart and canvas libraries.
For regulated buyers, Velt offers self-hosted data: content and personal information stay in the customer's database and object storage under a strip-on-write, merge-on-read model, while Velt keeps only structural identifiers. The company claims SOC 2 Type II, HIPAA with a BAA, 42 regions, a 99.999% SLA, more than 500,000 reviews running in production at OpenEnvoy and over fifty customers. Behind the product is Snippyly Inc., a San Francisco company from Y Combinator's Winter 2022 batch.
What it does
- Attach contextual comment threads to any element, document, cell or canvas, written by people or agents
- Turn every agent suggestion into a proposal a human approves or rejects before anything changes
- Run staged approval workflows with routing, conditions, quorum and return-to-author on rejection
- Apply approved changes through your own webhook, with a permanent record of who allowed what
- Keep an immutable, CSV-exportable audit trail of every human and agent action
- Let AI review agents flag issues and propose fixes as comments before a human looks
- Add presence, live cursors, CRDT co-editing, recording and huddles from the same SDK
When to use Velt / When not to
A quick filter to help you decide if Velt is the right fit.
When to use Velt
- SaaS product teams whose users must review or approve work before it ships
- Engineering teams adding agent features without granting agents write access to customer data
- Fintech, FP&A and compliance products that need staged sign-off and immutable records
- Sales enablement and content platforms where brand, legal or client approval gates every asset
- Startups that would otherwise spend two quarters building comments, notifications and audit trails in-house
When not to use Velt
- Products where no work is reviewed or approved by more than one user, a limit the site states itself
- Non-technical teams looking for a ready-made application: Velt is an SDK developers integrate
- Anyone expecting to run production on the free tier, which is restricted to development environments
- Buyers who need public self-serve pricing, since both paid tiers are contract-based only
- Mobile-first products expecting native iOS or Android apps, which Velt does not publish
How to use Velt
A typical end-to-end flow, from setup to results.
- Create a free API key on the Velt console, with no credit card required
- Install the front-end package with npm i @veltdev/react, adding @veltdev/node for backend endpoint mode
- Wrap your application in the VeltProvider component and pass it your API key
- Drop in the components you need, such as VeltComments, VeltCommentsSidebar or VeltNotificationsTool
- Alternatively, run the official MCP installer from Cursor, Claude Code, Windsurf, Copilot or Zed and let the agent do the wiring
- Define your approval workflows by posting a workflow definition to the Velt REST API
- Have your review agents publish their findings through the comment annotations endpoint
- Handle the change.applied webhook in your backend so approved changes are applied in your own system
- For self-hosted data, implement per-feature data providers and pass them to VeltProvider before identify runs
- Book a demo with the team once you outgrow the free development tier
Pros & Cons
Pros
- Review, approval and real-time collaboration in a single SDK, with no second vendor and no second contract
- Self-hosted data documented field by field, with a security-review inventory ready to hand over
- Fast integration: a first component claimed in under ten minutes and an average integration under thirty
- Very wide integration surface, with more than fifteen first-party integrations and over twenty editor, grid and chart libraries
- SOC 2 Type II, HIPAA with BAA, regular penetration tests, a 99.999% SLA and a public status page
- Billing on documents that actually saw review activity rather than on mere connections
- Named, quantified customer references from Google, X, Leadpages, Trumpet, Bigtincan and CloudFactory
Cons
- No public price for the paid plans: Growth and Enterprise are contract-based and require a demo
- The free Hacker tier is capped at 100 monthly active documents, one team member and development environments only
- Three of the seven review primitives, approval flows, suggestions and memory, are still in beta
- The most differentiating guarantees, from self-hosting and GDPR APIs to multi-region hosting, isolation, HIPAA and a DPA, are Enterprise-only
- Generic Termly legal pages, with terms dated 14 February 2023 still issued under the former Snippyly name while the footer reads Velt, Inc.
- No published subprocessor list and no documented opt-out from model training inside a tenant
- The SOC 2 report is available only under NDA, and the trust centre does not render without JavaScript
Pricing & Plans
Velt offers a permanent free plan. The Hacker tier is free forever and requires no credit card, but it is capped at 100 monthly active documents, a single team member and development environments only. The two paid tiers, Growth and Enterprise, are contract-based: no price is published, and access goes through a demo with the team. Billing is usage-based on monthly active documents, meaning documents on which a Velt feature performed CRUD operations during the month, rather than per seat or per connection. The only figure shown anywhere on the site is an illustrative 1,299 USD per month on the comparison page, at an unspecified volume, which cannot be read as an entry price.
- 100 monthly active documents
- all 15+ features
- pre-built components
- full customization
- basic webhooks
- real-time infrastructure
- development environments only
- contract-based monthly active documents
- all features
- basic webhooks and REST APIs
- real-time infrastructure
- Slack support
- 99.999% uptime SLA
- contract-based monthly active documents
- data self-hosting
- advanced webhooks and integrations
- GDPR APIs
- multiple region hosting (EU
- APAC
- NA)
- isolated server and data storage
Data, GDPR & hosting
A consolidated view of how Velt handles your data.
GDPR overview
Velt publishes a Termly-hosted privacy notice embedded on its privacy page. A Data Protection Officer is designated and reachable by email, with a postal address at Snippyly Inc., 650 California St, San Francisco. EEA and UK rights are listed explicitly: access, rectification, erasure, restriction, portability, objection and freedom from automated decision-making, plus the right to complain to a supervisory authority. International transfers rely on the European Commission's Standard Contractual Clauses, with copies available on request, while the servers themselves are in the United States. On the product side, Enterprise customers get GDPR REST APIs to retrieve, delete and check deletion of a user's data, EU data residency and a DPA. No Article 27 EU representative is named, and the site never claims GDPR compliance in so many words.
Who owns the data?
Velt's self-hosted data model leaves ownership with the customer. User-generated content and personal information stay on the customer's own infrastructure: comments in the customer's database, recordings in the customer's object storage, user identities in the customer's directory. Velt keeps only minimal structural identifiers, namely an opaque user id, a document id, status flags and timestamps. Each tenant is logically isolated and never co-mingled with another, and custom encryption is offered on some features at Enterprise level. On the vendor side, the privacy notice names Snippyly Inc. as the party responsible for deciding how personal information is processed.
Reuse rights
Velt states that each customer's data runs in isolated per-tenant storage, that it does not use one customer's content to train models for another, and that agent activity is never used for cross-customer model training; audit records of agent actions stay inside the customer's own tenant. The privacy notice adds that personal information is processed to provide, improve and administer the service, to communicate with users, for security and fraud prevention and to comply with law, on the basis of consent, contract, legal obligation, legitimate interest or vital interest. Cookies and tracking technologies are used, including Google Analytics remarketing, and Do-Not-Track signals are not honoured. No personal information has been sold in the preceding twelve months. Nothing published on the site describes an opt-out from model training inside a customer's own tenant.
Data retention & training
Hosting summary
Velt's privacy notice states that its servers are located in the United States and that information may be transferred to and processed in facilities there and in other countries. For customers who need something else, the product offers multiple region hosting across the EU, APAC and North America at the Enterprise tier, with residency pinning; the site claims 42 regions and names us-east, eu-west and ap-south among them. Enterprise customers also get an isolated server, database and storage, whereas lower tiers share infrastructure. The most far-reaching option is self-hosted data: user-generated content and personal information stay in the customer's own systems, whether MongoDB, PostgreSQL, AWS S3, MinIO, Google Cloud Storage or Azure Blob, while Velt retains only structural identifiers. Transfers out of the EEA and the UK rely on the European Commission's Standard Contractual Clauses. The marketing site itself resolves to an anycast address on Amazon's AS16509 network in the United States. No specific data centre operator is named for Velt's own cloud.
Things to keep in mind
Risks and trade-offs to weigh before adopting Velt.
- Approval fatigue: when every agent suggestion becomes a decision, reviewers start rubber-stamping and the audit trail records consent that was never really given
- Automation bias: a confidence score next to an agent proposal makes it feel already checked, and people under time pressure defer to it
- Skill erosion: teams that stop reviewing from scratch and only arbitrate machine output gradually lose the judgement the whole system depends on
- The memory primitive turns past decisions into precedent, which can quietly entrench a wrong call and make it harder to revisit
- An immutable audit trail names individuals: a compliance asset in a healthy culture, a surveillance and blame instrument in a bad one
- Data control depends on configuration: without self-hosting, content transits Velt's United States infrastructure, and self-hosting is Enterprise-only
- No published subprocessor list and no documented opt-out from training inside your own tenant leave two blind spots for a security review
Setup & Integrations
Technical difficulty
Low for a development team, out of reach for anyone else. Three steps cover the basic setup: install the package, wrap the application in VeltProvider and drop in components. Velt claims a first component in under ten minutes and an average integration in under thirty, and an official MCP server can do the provisioning from Cursor, Claude Code, Windsurf, Copilot or Zed. Self-hosted data is a different job: per-feature providers, customer-database-first write ordering, rollback, timeouts, retries and a multipart contract for binary files. Node and Python backend SDKs are provided. A front-end team is a prerequisite.
Deployment
Integrations
Behind Velt
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Velt.
Frequently asked questions
What does Velt actually do?
How is Velt different from Liveblocks?
Can an agent change data in my product without approval?
Where is the data stored, and can I self-host it?
Which frameworks and editors does Velt support?
How is Velt priced?
How long does integration take?
Does Velt train models on my content?
What is the minimum age to use Velt?
Should you pick Velt?
Velt is a serious piece of infrastructure for teams that need review, approval and traceability inside their own product rather than yet another standalone tool. Its strongest argument is coverage: the review primitives and a complete real-time collaboration layer arrive in the same SDK, under the same contract, with an unusually wide set of editor, grid, chart and canvas integrations. Its second is the self-hosted data model, documented field by field and explicitly built to survive a buyer's security review.
Maturity is uneven, and the site is reasonably honest about it. Comments, notifications, presence and multiplayer editing are the proven parts, backed by named customers and quantified results. The governance primitives that justify the current positioning, approval flows, suggestions and memory, are still marked beta, and the guarantees enterprise buyers care about most, from self-hosting and GDPR APIs to EU residency, HIPAA and a DPA, sit behind the Enterprise tier.
Cost is the main unknown. Prototyping is free and genuinely quick, but the free tier forbids production and both paid tiers are contract-based with no published price, so budgeting starts with a demo. The legal layer also lags the product: generic Termly documents, terms dated February 2023, still issued under the former Snippyly name, mentioning a fourteen-day free trial that the current pricing page does not offer.
It is worth evaluating if your product contains work that more than one person signs off on, and especially if you are adding agent features and your security team has already refused to give those agents write access. Ask for the real price at your expected volume, the roadmap out of beta, the text of the DPA and the SOC 2 report before committing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.