Security
https://api.verafiable.com
How VERA protects your data and our infrastructure.
Privacy-Preserving Architecture
VERA is designed so that customer documents never leave the customer’s environment. The platform operates on SHA-256 cryptographic fingerprints and structured metadata. Document content is not transmitted to, stored on, or accessible by VERA infrastructure.
Infrastructure Security
Encryption
All data encrypted in transit (TLS 1.2+) and at rest (AES-256). Database encryption managed by AWS RDS.
Access Control
Role-based access control (RBAC). Multi-factor authentication enforced on all infrastructure accounts (AWS, GitHub, Cloudflare). Least-privilege database roles.
Network Security
CloudFront CDN with Cloudflare edge security. HSTS enabled. Security group rules restrict traffic to minimum required paths.
Logging & Monitoring
CloudWatch alarms, CloudFront access logs, structured audit trail. Security events routed to alert channels.
Append-Only Enforcement
Decision Records and audit events are protected by database-level triggers that block UPDATE and DELETE operations. Hash chain integrity is maintained across credential rotations and infrastructure changes.
Code Security
GitHub 2FA with authenticator app. Branch protection on main. Dependency scanning enabled.
Compliance Alignment
VERA’s control framework is designed to align with SOC 2 Trust Services Criteria (Security). Policies, procedures, evidence collection, and gap remediation are documented and tracked. SOC 2 readiness is in progress.
VERA Platform LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB, certification pending) and maintains SAM.gov registration for federal procurement eligibility.
What VERA Does Not Do
VERA is not a payment processor, money transmitter, custodian, or bank. VERA does not hold, transfer, or have access to customer funds. VERA does not guarantee the prevention of fraud or unauthorized transactions. VERA provides verification infrastructure that produces auditable evidence — the enforcement and interpretation of that evidence is the responsibility of the integrating party.
Vulnerability Reporting
If you discover a security vulnerability in VERA’s public-facing infrastructure, please report it responsibly to adam@verafiable.com with the subject line “Security Report.” We will acknowledge receipt within 48 hours and provide a timeline for remediation.
Contact
VERA Platform LLC
adam@verafiable.com
844-427-0024