Security & Compliance

Enterprise-grade security, built into the platform

Protection, integrity and explainability are engineered into VeroOS, so compliance and risk teams can move fast without giving up control.

AI Governance

AI that works inside the rules you set

Vero AI reads your own live records, works inside the limits your administrators configure, and writes each prompt and answer to an activity log alongside the records it used and any human approval step. How those controls are set, and what the log holds, is laid out in full on the Vero AI page.

See how Vero AI is governed
Activity log · Facility LAFL0012

Risk score computed

Inputs captured & logged

09:41

Answer recorded

Response and records used, stored

09:41

Human review

Analyst approved

09:47

How we protect your data

Security controls across the stack

Controls are applied at every layer, from how data is encrypted and who can reach it through to how the platform is built, monitored and recovered.

Data protection

  • AES-256 encryption at rest
  • TLS 1.2 and 1.3 enforced end to end
  • Keys held in a managed key vault, rotated, and never exposed to the application
  • Data classified as public, internal, confidential or restricted, with encryption applied by classification

Access and identity

  • Multi-factor authentication enforced across internal accounts
  • Single sign-on via SAML 2.0, OpenID Connect and OAuth 2.0
  • Role-based access control with granular permissions
  • Just-in-time privileged access with approval workflows
  • Unique user IDs, with no shared accounts

Application security

  • Static and dynamic application security testing in the deployment pipeline
  • Automated vulnerability scanning
  • Independent penetration testing
  • Input and output validated and sanitized at every boundary
  • Separate development, test and production environments

Infrastructure and network

  • Segmented network with isolated front-end, back-end and database tiers
  • Firewall-protected boundaries with flow logging
  • Intrusion detection and prevention
  • Containerized deployment with automated patching
  • Hardened baseline configurations and a maintained asset inventory

Monitoring and response

  • Centralized logging with SIEM-based threat detection
  • Continuous review of security events
  • A documented incident response plan, exercised against simulated breach scenarios
  • Customer notification for incidents affecting their data or service
  • A complete audit trail of user activity

Resilience and recovery

  • Continuous backup with point-in-time recovery
  • Encrypted, geographically redundant backup storage
  • Deployment across multiple availability zones
  • A documented business continuity and disaster recovery plan
  • Recovery scenarios covered in incident response testing

Screened people

Employees, contractors and involved third parties are subject to background verification, including criminal screening where local law permits.

Trained teams

Security awareness training is required across the company, with additional role-specific training for the people who build and operate the platform.

Maintained policies

A documented policy set governs access control, encryption and key management, network security, secure development, data retention, change management and incident response.

AICPA SOC for Service Organizations seal

Independently audited

These controls are independently examined against the AICPA Trust Services Criteria for Security by Prescient Assurance LLC. The full report is available to customers and prospective customers on request.

Vendor due diligence

Security documentation, ready for your review

Request the full package for your vendor review. We work directly with your risk and security teams to answer whatever the process requires.

  • SOC 2 Type 2 report
  • Information security policies
  • Completed security questionnaire
  • Encryption and key management policy
  • System architecture overview
  • Business continuity and incident response plans
Request the security package

Found a security issue? Report it to security@vero-technologies.com and our team will respond directly.

See VeroOS on your book of business

A 30-minute walkthrough with people who've run the workflows you're modernizing.