Legal
Security at Verasity™
Our approach to product security, data protection, identity, and enterprise trust.
Last updated: May 2026
Security overview
Verasity™ is built for enterprise security teams. We follow an industry-aligned controls framework covering data protection, identity, secure development, monitoring, and incident response. Documentation is available under NDA.
Data encryption in transit and at rest
All customer data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 (or equivalent) at the storage layer. Key management is operated by the platform with rotation and access logging.
Access control
Access to customer data is restricted by role, requires MFA, and is logged. Least-privilege principles apply across the platform and the Verasity™ team.
SSO and SAML support
Verasity™ supports SAML 2.0 SSO, OIDC, and SCIM provisioning with Entra ID, Okta, Google Workspace, and other major identity providers.
Logging and monitoring
Authentication, administrative actions, and security-relevant events are logged. Logs are retained per customer policy and available for export to SIEM platforms including Splunk and Microsoft Sentinel.
Secure development lifecycle
Verasity™ follows a secure SDLC including peer code review, dependency scanning, static analysis, secret scanning, and pre-release security review for material changes.
Vulnerability management
Internal scanning, dependency monitoring, and third-party penetration testing run on a defined cadence. Findings are tracked to remediation with severity-based SLAs.
Incident response
Verasity™ maintains a documented incident response plan with on-call rotation, customer notification procedures, and post-incident review.
Backup and recovery
Data is backed up on a regular schedule with tested recovery procedures. RPO and RTO targets are documented and available under NDA.
Responsible disclosure
We welcome security researchers. Please report findings to security@verasity.ai. We commit to acknowledging reports promptly and coordinating responsible disclosure.
Contact
Security questions and documentation requests: security@verasity.ai.
Questions? Contact security@verasity.ai.