Trust
Security at VERIS
This page is maintained by Recrucial AB to answer common security and privacy questions about VERIS. It describes current practices, not an independent certification.
Effective 4 August 2026
Access and authentication
VERIS uses managed authentication, protected sessions, organization-scoped access controls, and role-based permissions. Sensitive administrative actions require recent identity verification. Access to customer records is constrained in the database and privileged operations are separated from browser access.
Credentials and data protection
Provider credentials and backend secrets are stored in protected systems and are not returned to the browser after entry. Network traffic uses encrypted transport. Security-sensitive actions and credential access are recorded for investigation and accountability.
Application safeguards
Public inputs are validated and rate-limited where abuse risk exists. Automated internal jobs require backend-only authorization. Payment callbacks are signature-verified and processed idempotently. VERIS separates test and live payment state.
Monitoring and response
VERIS records security events, provider health, operational failures, and administrative activity. Current reachability is published on the Status page. We investigate credible reports and prioritize containment, customer impact assessment, remediation, and notification where required.
Shared responsibility
Recrucial AB secures the VERIS application and its operating environment. Customers remain responsible for account membership, connected provider settings, credential rotation, application data, lawful AI use, output review, and the security of systems calling VERIS. Connected AI providers operate under their own controls and terms.
Compliance
VERIS does not claim certification or compliance with a particular framework on this page. Customers with contractual, regulatory, residency, or assessment requirements should contact us before relying on VERIS for regulated workloads.
Report a vulnerability
Send suspected vulnerabilities to security@veris.digital with reproduction steps and potential impact. Do not access other users' data, disrupt service, use destructive testing, or publicly disclose an unresolved issue.
We will acknowledge credible reports and coordinate remediation and disclosure in good faith. This is a reporting policy, not a bug bounty commitment.