Security at Veridion

You're trusting a compliance product with a read-only view of your stack. Here is exactly how we protect that trust — the same standard we help you meet.

Encryption in transit and at rest

All traffic to Veridion is encrypted with TLS. Integration credentials — the most sensitive data we hold — are encrypted at rest with AES-256-GCM before they ever touch the database, and are decrypted only at the moment a check runs.

Least-privilege, read-only integrations

Every connector is designed to work with read-only credentials, and the connection instructions tell you exactly which minimal scopes to grant. Veridion verifies settings; it never changes them. If you revoke a credential, the integration simply stops.

Per-organization isolation

Every record — controls, evidence, policies, devices, credentials — is scoped to your organization. All queries filter by organization, so no customer can ever read another customer's data.

Authentication you control

Sign-in is handled by Clerk, a SOC 2 Type II audited identity provider. Password rules, two-factor authentication, session management and revocation are available to every account, on every plan, including free.

Payments never touch our servers

Billing runs through Dodo Payments as merchant of record. Card numbers are entered on their PCI-DSS compliant checkout — Veridion never sees, stores, or processes payment card data.

A device agent that only reports

The optional device agent reads security posture — disk encryption, screen lock, OS updates — and reports it. It is a short, open script you can inspect before running, it makes no changes to the machine, and it can be removed at any time.

Auditor access that expires

Evidence-room links for auditors are read-only, expire automatically after 90 days, and can be revoked at any time. No auditor account, password, or standing access is ever created.

Breach notification

If we ever discover a breach affecting your data, we will notify you without undue delay, tell you what happened and what we are doing about it.

Sub-processors

We keep our vendor list short deliberately. Each sub-processor is itself independently security-audited:

VendorPurpose
VercelApplication hosting and delivery
SupabaseManaged Postgres database
ClerkAuthentication and session management
AnthropicAI policy drafting and assistant (Claude)
Dodo PaymentsPayment processing (merchant of record)

Found a vulnerability?

We welcome good-faith security research. Report vulnerabilities to hello@qubrise.com with enough detail to reproduce the issue. We will acknowledge your report quickly, keep you informed as we fix it, and credit you if you'd like. We will not pursue action against researchers who act in good faith and avoid privacy violations or service disruption.

Details on data collection, retention, and your rights are in our Privacy Policy.

Security at Veridion — How We Protect Your Data — Veridion