Trust Center

Built for security and privacy review.

Verasity™ is designed to pass enterprise security, privacy, and procurement reviews. This page summarizes our posture. Detailed documentation is available under NDA.

What we cover

Trust posture at a glance

Security overview

Verasity™ operates a defense-in-depth security program covering people, process, and technology. Tenancy isolation, least-privilege access, and continuous monitoring underpin every workload.

Privacy overview

We process customer data only to deliver the contracted service. Personal data is minimized, access is audited, and a Data Processing Addendum is available for enterprise customers.

AI governance

Models used in Verasity™ are inventoried, reviewed for safety and bias, and operated with prompt, output, and abuse logging. Customers can opt out of training-data use.

Data residency

Verasity™ is designed to support global enterprise deployment models, including regional hosting and data residency options where configured and contractually agreed. Customers with specific data residency, privacy, or regulatory requirements can request a data residency brief and security documentation.

Subprocessors

A current sub-processor list is maintained and made available under NDA. Material changes are notified in advance per the DPA.

Responsible disclosure

We welcome security research. Reports can be sent to security@verasity.ai with PGP. We coordinate timelines and acknowledge contributions in our hall of fame.

DPA availability

A standard Data Processing Addendum, SCCs where applicable, and a sub-processor list are available to enterprise customers on request.

SSO, SAML, SCIM

SAML 2.0 SSO and OIDC, plus SCIM provisioning, with Entra ID, Okta, Google Workspace, and other major IdPs.

Encryption

TLS 1.2+ in transit, AES-256 at rest, managed key rotation, and access logging on key material.

Secure SDLC

Threat modeling, code review, dependency scanning, SAST/DAST, infrastructure-as-code review, and continuous secret scanning across all repositories.

Incident response

Documented incident response plan with on-call rotations, severity tiers, customer notification commitments, and post-incident review.

Compliance readiness

Controls and evidence aligned to SOC 2, ISO 27001, HIPAA, PCI DSS, and OSFI expectations. Evidence packs and reports are available to enterprise customers.

Documentation under NDA

Detailed security architecture, pen test summaries, SOC 2 reports, and the sub-processor list are available under mutual NDA on request.

Request access

Security documentation under NDA

Under mutual NDA we share: SOC 2 Type II summary, ISO 27001 status, penetration test executive summary, security architecture overview, sub-processor list, DPA, BAA where applicable, and our incident response runbook overview.

Or email security@verasity.ai directly.

Talk to security & procurement

Book a security walkthrough or run a free risk scan. We work alongside your security review.

security@verasity.ai

Book a Demo