Security

Current pilot endpoint (HTTPS)
https://api.verafiable.com
VERA can produce hash-chained Decision Records over HTTPS for evaluation and shadow-mode pilots. We do not claim SOC 2 compliance or “production-grade” SLAs.

How VERA protects your data and our infrastructure.

Privacy-Preserving Architecture

VERA is designed so that customer documents never leave the customer’s environment. The platform operates on SHA-256 cryptographic fingerprints and structured metadata. Document content is not transmitted to, stored on, or accessible by VERA infrastructure.

Infrastructure Security

Encryption

All data encrypted in transit (TLS 1.2+) and at rest (AES-256). Database encryption managed by AWS RDS.

Access Control

Role-based access control (RBAC). Multi-factor authentication enforced on all infrastructure accounts (AWS, GitHub, Cloudflare). Least-privilege database roles.

Network Security

CloudFront CDN with Cloudflare edge security. HSTS enabled. Security group rules restrict traffic to minimum required paths.

Logging & Monitoring

CloudWatch alarms, CloudFront access logs, structured audit trail. Security events routed to alert channels.

Append-Only Enforcement

Decision Records and audit events are protected by database-level triggers that block UPDATE and DELETE operations. Hash chain integrity is maintained across credential rotations and infrastructure changes.

Code Security

GitHub 2FA with authenticator app. Branch protection on main. Dependency scanning enabled.

Compliance Alignment

VERA’s control framework is designed to align with SOC 2 Trust Services Criteria (Security). Policies, procedures, evidence collection, and gap remediation are documented and tracked. SOC 2 readiness is in progress.

VERA Platform LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB, certification pending) and maintains SAM.gov registration for federal procurement eligibility.

What VERA Does Not Do

VERA is not a payment processor, money transmitter, custodian, or bank. VERA does not hold, transfer, or have access to customer funds. VERA does not guarantee the prevention of fraud or unauthorized transactions. VERA provides verification infrastructure that produces auditable evidence — the enforcement and interpretation of that evidence is the responsibility of the integrating party.

Vulnerability Reporting

If you discover a security vulnerability in VERA’s public-facing infrastructure, please report it responsibly to adam@verafiable.com with the subject line “Security Report.” We will acknowledge receipt within 48 hours and provide a timeline for remediation.

Contact

VERA Platform LLC

adam@verafiable.com
844-427-0024