Summary

  • Velo Technologies Sdn Bhd is a Malaysian private company incorporated in 2018 whose public offer spans data-centre services, cloud, managed security, enterprise networking, managed IT and consultancy
  • Its Cyberjaya position and partnerships with Infinaxis, IPTP Networks and Shanghai International Data Port expand the infrastructure and service capacity it can offer without proving ownership of the underlying partner assets
  • The clearest named customer example is a disaster-recovery implementation for Qinetics MSP, while several larger case studies remain unnamed and therefore provide weaker evidence of repeatable customer scale
  • Publicly accessible financial indicators show 2025 revenue, assets and equity rising while operating and net profit measures fell, but absolute revenue, profit, cash and balance-sheet values remain undisclosed
  • The central commercial test is whether Velo can turn a broad partner-assisted service portfolio into repeatable managed-infrastructure contracts without delivery costs growing faster than revenue

A company becoming easier to see, but not yet easy to measure

Velo Technologies Sdn Bhd sits in a part of the digital-infrastructure market where company descriptions can become misleading very quickly. A provider may operate from a data centre without owning the building, sell cloud services without operating a hyperscale cloud, manage customer networks without owning the underlying fibre, and announce megawatts of capacity without those megawatts appearing on its balance sheet as owned infrastructure.

For a relatively small private company, understanding what it actually does therefore requires separating the services it sells, the infrastructure it can access, the partners it works with and the assets it can prove it controls.

That distinction is particularly important for Velo. The Malaysian company presents itself across data-centre services, cloud computing, managed security, managed IT, enterprise networking and professional IT consultancy. It has also announced partnerships involving data-centre capacity, international connectivity and artificial-intelligence-related services. Those activities give it a much wider commercial surface than a conventional local IT contractor, yet the public record does not support treating Velo as a large-scale owner of data centres, networks or cloud infrastructure.

The company was incorporated in Malaysia on 31 December 2018 under registration number 201801047183, with the legacy company number 1309215-D. Its known business address is at CSF TelcoHub1 in Cyberjaya, Selangor, placing it inside one of Malaysia's established concentrations of data-centre and technology infrastructure. Velo also identifies a regional office in Timor-Leste, although the available public material does not establish whether that office is operated through a separate legal entity.

Its footprint is therefore real, but the important question is what kind of footprint it is. The evidence points towards an infrastructure-services company that combines its own technical teams and service brands with capacity, platforms and reach supplied through other organisations. That can be a perfectly viable model. It can also be difficult to understand from the outside because the commercial proposition is broader than the company's visible corporate structure.

The same problem appears in Velo's financial information. EMIS identifies 2025 as its latest available financial year and reports revenue increasing by 5.91% from the previous year. Total assets rose by 10.55% and equity by 13.06%, indicating that the company continued to expand its financial base. Yet the accessible data does not disclose the absolute amount of revenue, assets, equity or profit, which makes it impossible to tell whether those percentage changes represent a business of several million ringgit, tens of millions, or something larger.

Profitability also moved in a less comfortable direction. EMIS reports that its net profit-or-loss measure declined by 49.14% in 2025 and operating profit fell by 41%. The accessible profile does not reveal the underlying values or even allow an outside reader to establish confidently whether the company remained profitable after the decline. It also reports lower net and operating profit margins, but not the absolute margin levels.

That combination makes Velo an interesting company to examine precisely because the conclusion cannot be reduced to either rapid growth or financial weakness. Revenue, assets and equity moved higher while profit measures deteriorated. At the same time, the company continued to form partnerships and widen the services it presents to customers. The public evidence therefore describes a business adding commercial reach while still leaving important questions about scale, capital intensity and returns unanswered.

For customers, suppliers and competitors in Malaysia's infrastructure market, those questions matter more than the number of services on a website. Velo's next stage will depend on whether it can convert a widening collection of capabilities and partnerships into repeatable customer contracts without allowing the cost of delivery to outrun revenue growth.

From a 2018 Malaysian company to a multi-service technology provider

Velo's legal identity is straightforward at the top level. It is a Malaysian private limited company incorporated at the end of 2018, and commercial registry sources derived from Companies Commission of Malaysia data identify Selangor as its state. Its registry descriptions cover information-technology services, telecommunications activities and the import and export of general-purpose machinery, categories broad enough to accommodate much of what the company does today.

The business Velo presents publicly is considerably more specific. Its service catalogue is organised around six principal areas: data-centre services, cloud computing, managed security, managed IT, enterprise networking and professional IT consultancy. That is an unusually wide span for a company whose industry-directory footprint suggests a relatively small workforce, and it provides the first clue to how Velo appears to be constructing its business.

Instead of concentrating on one narrow infrastructure product, it positions itself across several layers of the customer's technology environment. A customer could theoretically use Velo for data-centre space or associated infrastructure, private-cloud resources, networking, security and outsourced operational support. Professional consultancy then sits above those products as a way of designing or implementing the environment.

The advantage of that model is that the services can reinforce one another. A company moving servers into a data centre may need new connectivity, security configuration, backup services and ongoing monitoring. A business buying managed private cloud may also need disaster recovery and network management. If one provider can supply several of those functions, it has opportunities to increase the value of each customer relationship without having to win a completely new account every time it adds revenue.

There is, however, a difference between having a broad service catalogue and possessing all of the physical infrastructure required to deliver it independently. Velo's public record suggests that partnerships are an important part of the answer. Its data-centre relationship with Infinaxis, connectivity and managed-services relationship with IPTP Networks and later agreement with Shanghai International Data Port all extend what Velo can potentially offer without establishing that those counterparties or their assets belong to Velo.

This is where careful language becomes essential. TelcoHubX, Nebula Managed Private Cloud, Astrinox and Ultraconnect SD-WAN appear in Velo's public material as brands, operating descriptions or solutions. The available records do not justify treating them as subsidiaries. No parent company, subsidiary or equity affiliate of Velo has been verified from the accessible public information either.

The distinction sounds technical, but it changes how the company should be understood. A corporate group can grow by acquiring businesses and accumulating assets under common ownership. An infrastructure integrator or managed-services company can grow differently, combining internal capability with infrastructure, software and specialist services sourced through partners.

Velo's public development looks closer to the second pattern. That means its competitive position cannot be judged only by the size of its owned asset base. Its ability to bring together data-centre capacity, networking, cloud, security and operational support may be just as important.

It also means execution becomes central. Every additional partner, platform and managed service increases the number of technical and commercial interfaces the company has to control. The value of an integrated provider comes from making those interfaces less complicated for the customer, not transferring the complication to them.

That is a demanding proposition for any company. For a business with a publicly reported workforce of only 23 people — a PIKOM figure for which the measurement date is not disclosed — it raises an even more important question about how much of Velo's expanding service range is delivered internally, how much is automated and how much depends on counterparties.

The available information does not answer that question completely. It does, however, show enough customer and partnership activity to establish that Velo is more than a marketing shell around a list of technology terms. The company has named commercial relationships and a documented customer implementation. The task is to understand what those pieces collectively say about the business.

Cyberjaya gives Velo a useful place in Malaysia's infrastructure market

Location matters in digital infrastructure, and Velo's base in Cyberjaya is more than a postal detail. The company's known business and mailing address is at 3552, CSF TelcoHub1, Level 2, Jalan Teknokrat 6, 63000 Cyberjaya, Selangor. Cyberjaya has long been one of Malaysia's principal technology locations and has become increasingly relevant as investment in Malaysian data centres, cloud platforms and regional connectivity has accelerated.

Velo describes Cyberjaya as its head-office location. Its presence there puts the company physically close to infrastructure operators and enterprise customers without proving that it owns the facility from which it operates. That distinction matters because Velo uses the TelcoHubX name in connection with its data-centre activities, while public evidence identifies TelcoHubX as a company branding or operating designation rather than a separately verified corporate entity.

The company therefore needs to be considered as an operator and services provider before it is described as an infrastructure owner. Ownership would require evidence about the underlying land, building, power systems, mechanical infrastructure or corporate vehicle. The available research does not establish those points.

That does not make the data-centre proposition insignificant. Customers do not always need their service provider to own the building in which their equipment sits. Managed infrastructure markets contain many profitable businesses that lease capacity, purchase wholesale services or operate customer environments inside third-party facilities. What matters is whether responsibility is clear and whether the provider can reliably deliver the contracted service.

For Velo, Cyberjaya gives that model a practical base. Data-centre services can create the physical anchor for cloud, managed network, backup and security work. Once a customer's systems are located in or connected through an environment Velo manages, the relationship can become operational rather than transactional.

That change is commercially important. Selling hardware or completing a one-off infrastructure project produces revenue at a particular moment. Managing backups, networks, cloud environments, security operations or service desks can produce recurring relationships extending across months or years. Managed services also put the supplier much closer to the customer's everyday operations.

Velo's public case studies suggest that the company is trying to occupy precisely that position. It has described infrastructure migrations, outsourced IT operations and disaster-recovery work rather than limiting itself to rack space or equipment supply. The Qinetics MSP project provides the clearest independently named example.

The Cyberjaya location also gives Velo access to a market attracting much larger operators. That creates opportunity but raises the competitive standard. Customers purchasing infrastructure services in Malaysia can compare local providers with larger regional and multinational operators whose capital resources, certifications, engineering teams and established customer references may be substantially deeper.

A smaller company cannot normally win that contest simply by presenting the same list of services. It needs another advantage: closer customer attention, faster implementation, local flexibility, specialised technical expertise, more competitive pricing or a combination of those characteristics.

The public evidence does not establish which of these, if any, consistently differentiates Velo. What it does show is a company trying to widen the environment in which it can compete. Partnerships with other infrastructure businesses are central to that effort because they allow Velo to reach beyond the limitations of a small standalone footprint.

Cyberjaya is therefore best understood as Velo's operational centre rather than proof of the company's scale. Its significance comes from what the company can connect to that centre: customer workloads, partner capacity, cloud resources, networks and technical services.

The 2MW Infinaxis partnership is important, but it needs to be read carefully

The clearest infrastructure expansion associated with Velo came in May 2024, when Infinaxis Data Centre announced a strategic partnership involving an initial 2MW of capacity in Cyberjaya. The announcement also referred to an ambition for the partnership to generate RM100 million in overall value.

Both numbers are substantial enough to attract attention. Neither should be interpreted more broadly than the source supports.

The 2MW figure is a capacity commitment within the partnership. The available evidence does not establish that Velo owns a separate 2MW data-centre facility, owns the power infrastructure supporting it or has independently developed 2MW of new capacity on its balance sheet. The safer conclusion is that the partnership gives Velo a route to data-centre capacity as part of its commercial offering.

The RM100 million figure requires even more caution. The source describes it as the overall value the partnership aims to generate. It is not identified as a guaranteed contract payment to Velo, booked Velo revenue or capital committed directly to Velo. Treating it as any of those things would turn an ambition attached to a partnership into a financial result that has not been demonstrated.

Read on those terms, the announcement is still meaningful. Two megawatts can support a material volume of enterprise computing depending on rack density and allocation. For a small infrastructure-services provider, access to that capacity can increase the scale of customer opportunities it is able to pursue.

The arrangement also shows something about Velo's preferred route to market. Rather than waiting to develop a large standalone data-centre estate, the company can combine its customer relationships and managed services with infrastructure operated by another party. That reduces the requirement to reproduce every layer of the data-centre stack itself.

The trade-off is dependency. When a provider sells services built on another company's facility, customer performance can depend on both organisations. Capacity availability, power delivery, access procedures, maintenance, incident response and commercial terms all need to work together. The customer may contract with one company while several companies contribute to the outcome.

That is not unusual in digital infrastructure. Almost every cloud, network and data-centre service eventually depends on multiple operators. The important issue is whether the service provider manages those dependencies well enough that the customer does not have to.

Velo's own value proposition becomes clearer when the partnership is viewed this way. It does not have to become the biggest data-centre owner in Malaysia to create a useful business. It can instead try to become the organisation that assembles the required capacity, networks, cloud platforms and operational support for enterprise customers.

The commercial test is whether customers are willing to pay Velo for that integration rather than contract independently with the underlying infrastructure operators. If Velo can design, migrate, manage and support the environment, the company is selling responsibility rather than merely reselling capacity.

That can support higher-value customer relationships, but it also places more pressure on technical execution. The provider standing between the infrastructure and the customer becomes the first organisation blamed when something fails, even when the root cause belongs to another operator.

For that reason, the Infinaxis partnership matters less as a headline capacity number than as evidence of the role Velo is trying to play. The company appears to be building an infrastructure platform through access and integration as much as through ownership.

Whether that approach scales successfully will depend on utilisation and customer conversion. Public material does not disclose how much of the 2MW commitment has been sold, how contracts are structured, whether customers contract with Velo or Infinaxis for individual components, or how the economics are divided between the two parties.

Those missing details prevent a meaningful revenue model from being constructed. They should also stop outside observers from multiplying an assumed price per kilowatt by 2MW and treating the result as Velo's potential revenue. The relationship may include wholesale capacity, shared commercial responsibilities or services priced in several different ways.

What can be said is narrower. Velo has secured a visible data-centre relationship that gives it a stronger infrastructure story than a purely office-based managed-service provider. The business now has to show that the capacity can support sustained customer activity rather than remain primarily a partnership announcement.

Partnerships extend Velo's reach without changing who owns what

The same pattern can be seen in Velo's other partnerships. In December 2024, the company signed a memorandum of understanding with IPTP Networks in Ho Chi Minh City. The stated areas of collaboration included global connectivity, IT outsourcing and solutions, data-centre services and managed services.

IPTP operates in areas that complement Velo's service stack, particularly international connectivity. For a Malaysian provider trying to support customers beyond a single local facility, access to wider network reach can be commercially useful. Enterprise infrastructure increasingly crosses borders, whether because applications are hosted in several countries, staff work remotely or companies need disaster-recovery and cloud environments in different locations.

The agreement should nevertheless be understood as an MoU rather than evidence of a disclosed revenue contract. No contract value is publicly available from the material reviewed. There is also no basis for treating IPTP as part of Velo's corporate group.

That boundary becomes even more important with Velo's May 2025 memorandum of understanding with Shanghai International Data Port. The agreement described collaboration around AI Model-as-a-Service platforms, biomedical data integration, intelligent mobility ecosystems and AI talent development.

The subject matter is ambitious. Artificial intelligence, biomedical data and intelligent mobility place Velo's name alongside areas attracting significant infrastructure investment. But an MoU defines an intention or framework for collaboration; it does not by itself show that production systems have been deployed, that customers are paying for those systems or that either party has acquired an equity interest in the other.

The available evidence specifically does not support an equity relationship between Velo and Shanghai International Data Port. That distinction matters because partnerships can often be mistaken for group expansion when companies publish announcements containing phrases such as strategic collaboration.

For Velo, these partnerships are more useful when treated as evidence of capability-building rather than proof of completed scale. They show which problems the company wants to be able to solve and which external organisations it considers useful in solving them. They also reveal a widening geographical orientation, from Cyberjaya towards Vietnam, China-linked technology relationships and the company's separate reference to a Timor-Leste regional office.

There is a coherent strategy underneath those announcements. Velo is trying to sit between enterprise customers and an increasingly complex collection of infrastructure. The customer may need local data-centre capacity, international connectivity, private cloud, security, disaster recovery and specialist application environments. Velo's opportunity is to package those requirements into a manageable service.

That strategy can work without large-scale ownership, but it creates a different type of company from a vertically integrated infrastructure operator. Its most important assets may include engineering capability, customer relationships, commercial agreements and operational processes rather than only physical plant.

The risk is that a broad partner ecosystem can look larger on paper than it is economically. Every MoU needs to progress into an implemented service, paying customer or demonstrable operating capability before it contributes materially to the business. Announcements provide evidence of direction; contracts and utilisation provide evidence of commercial conversion.

Velo's public record contains both types of evidence, but much more of the first than the second. That is not surprising for a private company whose customers may require confidentiality. It does mean that readers should distinguish carefully between relationships that have been announced and business that can be independently observed.

The Qinetics MSP engagement is useful because it moves beyond this ambiguity. It gives a view of how Velo's broad service proposition can translate into a defined customer problem.

The Qinetics project shows what Velo looks like when the service catalogue becomes actual work

Among Velo's publicly visible customer evidence, the most useful example is a disaster-recovery implementation for Qinetics MSP. Unlike unnamed company case studies, the project is associated with an identifiable customer review and includes information about scope, duration and team size.

The project ran from January 2024 to February 2025 and involved a Velo team reported as two to five people. Its scope included enterprise backup software, an off-site disaster-recovery hosting environment, configuration of backup schedules and retention policies, monitoring alerts, disaster-recovery simulation, documentation, training and post-implementation support.

That list is important because it shows how several parts of Velo's service portfolio fit together. The job was not simply to sell backup software or provide storage capacity. It required Velo to configure the environment, establish operational procedures, test recovery, document the system and continue supporting it.

In practical terms, disaster recovery is a useful test of a managed-services provider. A backup system is valuable only if data can be restored when required. That means the provider must manage software, infrastructure, procedures, monitoring and customer expectations together.

The Qinetics project therefore provides stronger evidence of Velo's operating model than a general description of cloud or data-centre services. It suggests that the company is capable of assigning technical staff to a customer environment over an extended period and remaining involved after initial implementation.

The project also shows why Velo's combination of services can make commercial sense. Backup and disaster recovery sit at the intersection of infrastructure, networking, cloud and operations. A provider able to manage several of those layers can take responsibility for an outcome rather than delivering only one component.

The contract value was confidential, so the project cannot be used to estimate Velo's revenue. Nor does one customer engagement demonstrate that the same model has been replicated across a large installed base. It is best treated as proof that the capability has been delivered at least in this documented case.

That distinction is central to analysing a private technology company. A case study can establish that something happened. It cannot establish the size of the business built around it unless volumes, contract values or customer counts are also available.

For Velo, the project nevertheless reduces one of the uncertainties created by its wide service catalogue. It demonstrates that at least some of those capabilities are being used together in real customer work rather than existing only as separate marketing categories.

The small project team is also informative. A two-to-five-person team working on backup, disaster recovery, testing and support is consistent with a service business where technical specialists manage several customer environments rather than requiring a large dedicated staff for every contract.

That can create operating leverage if processes and platforms are standardised. The same tools, monitoring systems and engineering practices can potentially be applied across multiple customers. The challenge is maintaining service quality as the customer base expands.

For a company listed with 23 employees by PIKOM, that operating model is likely to matter considerably. Even allowing for an unknown measurement date and the possibility that the workforce has changed, Velo does not appear to have the headcount of a large systems integrator. It therefore needs either a tightly managed internal team, substantial automation, extensive partner support or some combination of the three.

The available public evidence does not disclose Velo's internal staffing allocation. We do not know how many employees work in networking, cloud, security, sales or support, nor whether additional contractors are regularly used. The Qinetics project offers only a small window.

It is still a useful window because it shows where the company's value can be created. The infrastructure underneath the service may come from several parties, but Velo's engineers are the people expected to make the customer's backup and recovery process work as a complete system.

That is the difference between infrastructure access and managed infrastructure. The first gives a company something to sell. The second requires it to accept responsibility for the result.

Velo's unnamed case studies broaden the picture, with an important limitation

Velo's own website adds several case studies that describe more substantial enterprise environments, although the customers are not named. One involves the relocation of data-centre and network infrastructure for what Velo describes as a leading or top-tier Malaysian retail bank. Another describes total IT infrastructure outsourcing and round-the-clock network-operations and service-desk support for a leading Malaysian certification authority.

A third case study describes physical and virtual infrastructure migration for a Malaysian Tier-3 carrier-neutral data-centre operator. Together, these examples suggest experience across financial services, trust or certification infrastructure and data-centre operations.

They also fit the same commercial model visible in the Qinetics project. Velo is presenting itself as a company that takes existing enterprise infrastructure and moves, operates or protects it. This is different from a company whose primary business is selling standardised software subscriptions.

Migration projects place the provider inside the customer's most sensitive infrastructure transitions. Servers, virtual machines, networks and associated services have to be moved without unacceptable disruption. Outsourcing engagements go further by transferring some daily operational responsibility to the service provider.

If accurately represented, those projects would be valuable references for a smaller infrastructure company. Banks and certification-related businesses can have demanding requirements for availability, security and operational discipline. Data-centre operators themselves are technically sophisticated customers.

The evidence boundary is equally important. These are Velo's own case studies, and the customers are not named in the accessible material. That means an outside reader cannot independently confirm the identities, contract values or each customer's description.

The correct use of these examples is therefore to say that Velo reports having completed the work, not to present unnamed institutions as independently verified customers. That may appear like a small editorial distinction, but it prevents company marketing from being transformed into external fact.

There are legitimate reasons for customer anonymity. Enterprise technology contracts often contain confidentiality provisions, and financial institutions can be particularly cautious about exposing details of their infrastructure. The absence of a customer name does not imply that the project did not happen.

It simply changes the strength of the evidence available to an outside observer. Qinetics can be identified and associated with a public review. The bank, certification authority and data-centre operator cannot.

Viewed together, the cases still provide a useful indication of the type of work Velo is pursuing. The recurring theme is operational responsibility around business-critical infrastructure. That includes migration, hosting, backup, monitoring and ongoing support rather than only equipment resale.

This helps explain why Velo has continued to add network, security, private-cloud and data-centre relationships around the core business. Each additional capability increases the number of infrastructure problems the company can attempt to solve without handing the customer to a different integrator.

The commercial opportunity is straightforward. A customer that trusts Velo with one migration or disaster-recovery project may later buy managed network, security or cloud services. The reverse can also happen: a customer using ongoing managed services may ask Velo to undertake a larger infrastructure transition.

The harder part is creating repeatability. Bespoke projects can consume large amounts of engineering time, making revenue growth expensive. Standardised managed services can improve the economics, but only if customers accept common platforms and processes.

Velo's public material does not reveal where the balance currently sits between project revenue and recurring service revenue. That missing information is significant because the two models produce very different financial profiles.

A business dominated by one-off projects may show uneven margins depending on equipment costs, staffing and project timing. A mature managed-services business can potentially generate more predictable recurring revenue, but usually requires continuing investment in service desks, monitoring, security and skilled staff.

The deterioration in Velo's reported profit measures in 2025 makes this distinction more relevant. Without the underlying accounts, there is no responsible way to say what caused the decline. But understanding the mix between projects and recurring services would help explain whether the company is absorbing expansion costs, experiencing weaker project margins or facing some other pressure.

For now, the case studies establish capability rather than economics. They tell us what Velo says it can do and, in the Qinetics example, what it has demonstrably done. They do not tell us how profitable each type of work is.

A workforce of 23 would make operating discipline unusually important

PIKOM's member directory reports 23 employees for Velo Technologies. The source does not disclose the measurement date, so the number should not be treated as a precise current headcount. A separate profile from The Manifest and Clutch places the company in the broader range of 10 to 49 employees, which is directionally consistent with a relatively small organisation.

Even with that qualification, the figure changes how Velo's service portfolio should be interpreted. Data centres, cloud computing, managed security, managed IT, enterprise networking and professional consultancy can each support specialist companies on their own. Providing all six areas with a small workforce requires the organisation to be selective about what it performs internally.

A small technical company can cover a surprisingly broad range if it relies on standard platforms and experienced engineers. It can also extend its delivery capacity through infrastructure partners, vendors and automation. The relevant question is therefore not whether 23 employees could physically perform every activity described on Velo's website, but how responsibilities are divided.

The Qinetics project gives one example of a compact team managing a meaningful assignment. A two-to-five-person implementation team is not inconsistent with specialised infrastructure work, particularly when the underlying software and hosting platforms already exist.

The challenge appears when several customers require urgent attention at the same time. Managed services are judged during failures rather than during sales presentations. A network outage, backup problem or security incident can require experienced personnel immediately, regardless of how many other projects are underway.

For that reason, service management becomes part of Velo's competitive position. Monitoring, escalation procedures, documentation and clear partner responsibilities can allow a small team to support more customers. Weak processes create the opposite effect, forcing senior engineers into repetitive incident work and limiting growth.

Workforce scale also affects the economics of geographic expansion. Velo identifies a regional office in Timor-Leste, but the public record does not establish a separate legal entity or disclose its staffing. Supporting another market can expand the customer base, but it also introduces travel, local support and commercial-management requirements.

The same applies to partnerships in Vietnam and China-linked technology ecosystems. A regional network of relationships can make a 23-person company appear much larger from a customer's perspective. That is useful only if the organisation can maintain accountability across those relationships.

There is no public evidence showing that Velo has failed to do so. Equally, the available information is not detailed enough to conclude that its operating structure is already highly scalable.

The more defensible observation is that people and process are likely to be constraints worth watching. Unlike a software company, Velo cannot serve infrastructure customers entirely through code. Engineering, customer support, physical coordination and incident management still require human attention.

If the company continues to expand its customer base and convert more partnership capacity into active services, headcount or productivity should eventually respond. A growing workforce would be one indication that the business is adding delivery capacity. Stable headcount accompanied by stronger financial performance could instead suggest increasing automation or better utilisation.

Without dated workforce data, neither pattern can yet be observed confidently. The 23-person figure remains a useful scale marker, not a complete description of Velo's current organisation.

Timor-Leste hints at a regional ambition beyond Malaysia

Velo's own company information identifies a regional office in Timor-Leste alongside its Cyberjaya head office. Public information does not establish whether the Timor-Leste operation is incorporated separately, how many people work there or how much revenue it contributes.

Those gaps prevent the office from being treated as evidence of a substantial regional business. It is nevertheless notable because Timor-Leste is very different from Malaysia's mature Cyberjaya infrastructure environment.

A smaller market can create different opportunities for an infrastructure-services company. Customers may have fewer specialist providers available locally, while governments, telecommunications companies and enterprises can still require cloud, cybersecurity, networking and business-continuity expertise.

A regional office can therefore have commercial value even if the local market is not large. It can provide a base for customer relationships and technical coordination while allowing the company to draw on platforms and engineering resources located elsewhere.

That model fits Velo's broader structure. Rather than replicating an entire infrastructure stack in every country, the company can potentially combine local presence with regional networks, data-centre partners and central technical teams.

The obvious limitation is that a stated regional office does not disclose activity levels. Public evidence reviewed for this profile does not identify a major Timor-Leste customer, local subsidiary or separate employee count. It would therefore be premature to describe Velo as having a large international operation.

The office is better interpreted as evidence of reach and intent. Together with its IPTP agreement in Vietnam and Shanghai International Data Port collaboration, it shows that Velo does not present its business as purely Malaysian.

Whether those connections become economically important will depend on signed customer work. Geographic dots on a company map are useful only when transactions begin moving between them.

Cloud, networking and security turn the data-centre relationship into a wider proposition

Velo's cloud service is presented partly through the Nebula Managed Private Cloud name. The available evidence treats Nebula as a service or product brand rather than a separate company. That distinction is again useful because it keeps the analysis focused on the service itself.

Private cloud sits naturally next to Velo's data-centre business. An enterprise may want dedicated or logically isolated computing capacity without operating all of the infrastructure itself. The service provider can manage the environment while the customer retains greater control than it would typically have in a purely public-cloud model.

Velo's enterprise networking proposition includes the Ultraconnect SD-WAN name, another service brand rather than a verified subsidiary. SD-WAN is relevant because cloud and distributed infrastructure depend heavily on connectivity between sites, users and applications.

Managed security adds another layer. Velo associates the Astrinox name with cybersecurity, although the available evidence does not establish a separate legal entity or an equity relationship around that brand. The company also states that it has obtained cybersecurity-related licensing from Malaysia's National Cyber Security Agency, a point that requires qualification because independent confirmation of the exact current licence was not located in the accessible regulator material.

Taken together, these products show an effort to move from infrastructure placement towards infrastructure operation. The data-centre facility gives customer systems somewhere to run. Cloud services provide computing resources, networking connects them, security protects them and managed IT keeps the environment functioning.

That is a logical service stack. It is also a crowded one.

Large telecommunications operators, data-centre companies, global cloud providers, systems integrators and specialised managed-service firms can all address parts of the same customer problem. Velo therefore competes not only with companies that look exactly like it but also with customers' ability to assemble the services from several different suppliers.

Its commercial argument has to be that integration adds value. A customer choosing Velo should ideally spend less time coordinating the underlying providers because Velo performs that work on its behalf.

That promise becomes more valuable as infrastructure becomes more complex. Hybrid cloud, cybersecurity requirements, multiple sites and disaster-recovery arrangements create many interfaces. A mid-sized enterprise may not want to employ a specialist team for every layer.

At the same time, integration increases the provider's responsibilities. If Velo is managing the full environment, the customer is unlikely to care which underlying supplier caused an incident. Velo remains the organisation expected to coordinate the fix.

This is why the company cannot be assessed only through product breadth. Operational accountability is the actual product underneath a managed-service catalogue.

The public case studies provide some evidence that Velo understands that role. Backup testing, service-desk support, infrastructure migration and post-implementation support all extend beyond the point of sale.

The missing piece is scale. We do not know how many customers use Nebula, Ultraconnect or Astrinox, how much recurring revenue those products generate, or how many engineers support each platform.

Those numbers would reveal whether Velo has built several meaningful service lines or is still in the process of turning a broad technical capability into a larger commercial operation.

The financial data points to growth with pressure underneath

Private-company financial analysis often begins with a problem: the numbers most useful to readers are not publicly accessible. Velo is a good example.

EMIS identifies 2025 as the latest year for which it has financial data and updated its company profile on 15 January 2026. The publicly accessible portion provides percentage movements but not the underlying ringgit amounts.

Revenue increased by 5.91% year on year. Total assets rose by 10.55%, while total equity increased by 13.06%. Those three movements show that the company was not standing still.

The profitability indicators moved in the other direction. EMIS reports a 49.14% decline in the company's net profit-or-loss measure and a 41% reduction in operating profit. It also displays a 3.49% decline in net profit margin and 4.22% decline in operating profit margin, although the accessible page does not establish whether those changes should be read as percentage points or relative percentage movements.

Return on equity is shown as having declined by 14.13%. Again, the absolute return is not publicly visible.

It would be tempting to turn those figures into a simple story: Velo is growing revenue but sacrificing profits to expand. The evidence does not go far enough to support that conclusion.

The direction is visible, but the cause is not. Profit could have been affected by staff costs, hardware purchases, depreciation, financing, project mix, expansion expenditure, pricing, one-off items or several other factors. Without the financial statements, assigning the decline to one cause would be speculation.

The absolute numbers matter just as much. A 49.14% decline from a large profit and the same percentage decline from a very small profit describe different businesses. Because EMIS does not reveal whether the net profit-or-loss figure remained positive, even saying that Velo was profitable in 2025 would go beyond the accessible evidence.

The relationship between revenue and assets is another area where caution is required. Data-centre and managed-services businesses can have very different capital structures depending on whether they own facilities, lease capacity, purchase hardware for customers, resell third-party services or operate infrastructure through partners.

That makes employee-based revenue estimates particularly unreliable. A company with 23 employees could handle substantial contract value if much of the underlying infrastructure is purchased from partners. It could also have relatively modest revenue if its projects are smaller. There is not enough evidence to choose responsibly between those possibilities.

The financial percentages still tell a useful story when kept within their limits. Velo entered 2025 with a business that continued adding revenue, assets and equity but generated weaker profit measures than the previous year.

For management, that creates a clear economic challenge. Revenue growth becomes less valuable if each additional ringgit of activity produces substantially less operating profit. The company needs the services and partnerships it is building to improve utilisation and recurring revenue without requiring costs to rise at the same pace.

Managed services can help if customers remain under contract and use standardised platforms. Data-centre capacity can help if committed infrastructure is filled with paying workloads. Network and security products can help if they are attached to existing accounts rather than requiring an entirely separate sales effort.

The reverse is also possible. A broad service catalogue can increase training, staffing, software and support costs before customer volumes become large enough to absorb them. New market development and partnership work can consume management attention even when revenue takes time to follow.

The public accounts do not reveal where Velo sits on that path. They do, however, make profitability one of the most important areas to watch.

A future period showing both stronger revenue and recovering operating margins would suggest that the broader platform is beginning to deliver more efficiently. Continued revenue growth accompanied by further profit deterioration would raise harder questions about pricing, utilisation and cost structure.

For now, the important point is simpler: Velo is showing growth, but the available financial data does not support describing that growth as uniformly stronger business performance.

The ownership structure is simple in percentage terms and opaque in identity

Corporate ownership is another area where Velo's public record stops halfway.

EMIS exposes two ownership entries, each at 50%. That makes the reported percentage structure unusually simple: two shareholders, equal economic stakes.

The names of those shareholders are not available on the accessible profile. Their nationality or jurisdiction is also not available, and neither are the underlying share counts, issue dates or total issued capital.

Those details can be obtained through Malaysian corporate-information products, including SSM e-Info, but the relevant records require authenticated or paid access. The same limitation applies to the company's current statutory directors, company secretary, registered office and auditor.

Ben Chin is publicly identified by Velo and PIKOM as the company's founder and chief executive. That makes him a central figure in the operating business. It does not establish that he is currently a statutory director or one of the two 50% shareholders.

There is a natural temptation to infer ownership from the founder title, particularly in a relatively small private company. That would be an error. A founder can own a company, share ownership with others, sell shares or continue as chief executive without holding the percentage an outside observer might expect.

No accessible evidence reviewed for this profile identifies Velo's ultimate beneficial owners. The two 50% stakes therefore should remain unnamed unless statutory or other authoritative records establish the identities.

The lack of public names does not itself imply a governance problem. Velo is a private Malaysian company, not a publicly listed corporation required to publish the same level of shareholder and board information to the market.

It does, however, limit external analysis. Ownership can influence strategic decisions, related-party relationships, capital availability and succession. With two equal shareholders, governance arrangements may also become particularly important if the owners disagree, although there is no evidence of such a dispute in Velo's case.

The same evidence discipline applies to group structure. No parent company, subsidiary or equity affiliate has been verified from the accessible records. The company's service brands and commercial partners therefore should not be placed underneath Velo on an ownership chart simply because they are closely associated with its operations.

This is particularly important for understanding the apparent size of the business. A website can contain many brands, partnerships and offices while the underlying legal entity remains relatively compact.

Velo's organisational picture currently looks exactly like that: one verified Malaysian company, a founder and CEO, two unnamed 50% shareholders, a Cyberjaya head office, a stated Timor-Leste regional office and several service brands and non-equity partnerships.

More detailed SSM records could materially refine that picture. Until they are available, the gaps should remain gaps rather than being filled with assumptions.

Regulatory claims add credibility only where the licence can be pinned down

Velo states that it is licensed by the Malaysian Communications and Multimedia Commission and records an Application Service Provider licence as a milestone dating from 2019. The company also states that it received cybersecurity-service-provider licensing under Malaysia's National Cyber Security Agency in 2025.

Both claims are relevant to the types of services Velo sells. Telecommunications and cybersecurity activities can require regulatory permissions, and customers may consider those permissions when selecting providers.

The accessible research did not independently verify Velo's exact current MCMC licence number in the available regulator register. It also did not identify the company's precise NACSA licence through the accessible regulator search material.

The appropriate description is therefore that the licences are company-reported, with the exact current identifiers not independently confirmed in the sources reviewed.

This matters because regulatory references can easily become stronger as they pass through secondary articles. A company says it received a licence, an article describes it as licensed, and a later profile treats the licence as independently verified. Each repetition makes the statement look more authoritative even when the original evidence has not changed.

There is no specific reason in the available material to conclude that Velo's statements are incorrect. The point is instead that verification status should travel with the claim.

For customers, the exact licence can be more important than the marketing language around it. A licence number, category and validity period allow a procurement or compliance team to check whether the authorisation covers the service being purchased.

As Velo pursues security and network-related business, publishing or making those details readily available would make its regulatory position easier for outsiders to assess.

The same approach applies to legal risk. Searches of accessible sources did not identify material litigation, insolvency, winding-up proceedings or regulatory penalties involving the exact legal entity Velo Technologies Sdn Bhd.

That finding is useful but should not be turned into a guarantee that no private, unreported or registry-only proceeding exists. Public-source research can establish that no event was located within the search scope; it cannot prove a universal absence.

One similarly named company, Velocity Technology Sdn Bhd, appeared in a 2025 Industrial Court case. It is a different legal entity and should not be associated with Velo Technologies.

That kind of false positive is another reason company identifiers matter. In a market containing many similarly named technology businesses, the registration number can be more reliable than the brand name when assessing corporate events.