Trust

Security at VERIS

This page is maintained by Recrucial AB to answer common security and privacy questions about VERIS. It describes current practices, not an independent certification.

Effective 4 August 2026

Access and authentication

VERIS uses managed authentication, protected sessions, organization-scoped access controls, and role-based permissions. Sensitive administrative actions require recent identity verification. Access to customer records is constrained in the database and privileged operations are separated from browser access.

Credentials and data protection

Provider credentials and backend secrets are stored in protected systems and are not returned to the browser after entry. Network traffic uses encrypted transport. Security-sensitive actions and credential access are recorded for investigation and accountability.

Application safeguards

Public inputs are validated and rate-limited where abuse risk exists. Automated internal jobs require backend-only authorization. Payment callbacks are signature-verified and processed idempotently. VERIS separates test and live payment state.

Monitoring and response

VERIS records security events, provider health, operational failures, and administrative activity. Current reachability is published on the Status page. We investigate credible reports and prioritize containment, customer impact assessment, remediation, and notification where required.

Shared responsibility

Recrucial AB secures the VERIS application and its operating environment. Customers remain responsible for account membership, connected provider settings, credential rotation, application data, lawful AI use, output review, and the security of systems calling VERIS. Connected AI providers operate under their own controls and terms.

Compliance

VERIS does not claim certification or compliance with a particular framework on this page. Customers with contractual, regulatory, residency, or assessment requirements should contact us before relying on VERIS for regulated workloads.

Report a vulnerability

Send suspected vulnerabilities to security@veris.digital with reproduction steps and potential impact. Do not access other users' data, disrupt service, use destructive testing, or publicly disclose an unresolved issue.

We will acknowledge credible reports and coordinate remediation and disclosure in good faith. This is a reporting policy, not a bug bounty commitment.