Built for security and privacy review.
Verasity™ is designed to pass enterprise security, privacy, and procurement reviews. This page summarizes our posture. Detailed documentation is available under NDA.
Trust posture at a glance
Security overview
Verasity™ operates a defense-in-depth security program covering people, process, and technology. Tenancy isolation, least-privilege access, and continuous monitoring underpin every workload.
Privacy overview
We process customer data only to deliver the contracted service. Personal data is minimized, access is audited, and a Data Processing Addendum is available for enterprise customers.
AI governance
Models used in Verasity™ are inventoried, reviewed for safety and bias, and operated with prompt, output, and abuse logging. Customers can opt out of training-data use.
Data residency
Verasity™ is designed to support global enterprise deployment models, including regional hosting and data residency options where configured and contractually agreed. Customers with specific data residency, privacy, or regulatory requirements can request a data residency brief and security documentation.
Subprocessors
A current sub-processor list is maintained and made available under NDA. Material changes are notified in advance per the DPA.
Responsible disclosure
We welcome security research. Reports can be sent to security@verasity.ai with PGP. We coordinate timelines and acknowledge contributions in our hall of fame.
DPA availability
A standard Data Processing Addendum, SCCs where applicable, and a sub-processor list are available to enterprise customers on request.
SSO, SAML, SCIM
SAML 2.0 SSO and OIDC, plus SCIM provisioning, with Entra ID, Okta, Google Workspace, and other major IdPs.
Encryption
TLS 1.2+ in transit, AES-256 at rest, managed key rotation, and access logging on key material.
Secure SDLC
Threat modeling, code review, dependency scanning, SAST/DAST, infrastructure-as-code review, and continuous secret scanning across all repositories.
Incident response
Documented incident response plan with on-call rotations, severity tiers, customer notification commitments, and post-incident review.
Compliance readiness
Controls and evidence aligned to SOC 2, ISO 27001, HIPAA, PCI DSS, and OSFI expectations. Evidence packs and reports are available to enterprise customers.
Documentation under NDA
Detailed security architecture, pen test summaries, SOC 2 reports, and the sub-processor list are available under mutual NDA on request.
Security documentation under NDA
Under mutual NDA we share: SOC 2 Type II summary, ISO 27001 status, penetration test executive summary, security architecture overview, sub-processor list, DPA, BAA where applicable, and our incident response runbook overview.
Or email security@verasity.ai directly.
Talk to security & procurement
Book a security walkthrough or run a free risk scan. We work alongside your security review.
security@verasity.ai