Security and sovereignty are the product. Verificate is engineered so that sensitive data and decisions stay inside your boundary. This Trust Center documents our controls, mapped to the AICPA SOC 2 Trust Services Criteria and an ISO/IEC 27001:2022 control framework — stated accurately, the way an enterprise security team would want to verify them.
We publish our security posture the way an enterprise security team would want to verify it — accurately.
Controls designed and mapped to the AICPA Trust Services Criteria; a SOC 2 Type II examination is on our roadmap. We do not represent a completed attestation until a report is issued; audit status and any report are available under NDA.
Information security managed under an ISO/IEC 27001:2022 control framework, evidence-based and independently reviewed as controls mature; formal certification is on our roadmap. We do not claim certification until an accredited certificate is issued.
Our hosted service runs on AWS (Sydney region) and Cloudflare — infrastructure that is itself independently certified to SOC 2 and ISO/IEC 27001 — and our products can run entirely inside your own boundary, on-premises or air-gapped, so the most sensitive data need never leave the building.
Our controls address each of the five criteria:
Information security is managed under an ISO/IEC 27001:2022 control framework — a documented control matrix mapped to Annex A, operated on evidence and independently reviewed as each control matures. Coverage spans the four Annex A themes:
Information-security policies, asset & access management, supplier and cloud-service security, classification, incident management and continuity (A.5).
Screening, security responsibilities, awareness and access on joining, changing and leaving (A.6).
Secure facilities and equipment for the managed-cloud substrate; sovereign / air-gapped options remove the surface entirely (A.7).
Cryptography, secure development (SDLC), logging & monitoring, vulnerability & threat management, data masking, backup and secure configuration (A.8).
A control is recorded as operating only when a named owner has attached current evidence and an independent reviewer has accepted it. Certification is on our roadmap; we do not claim it until an accredited certificate is issued.
Verificate products are CPU-native and architected for zero network egress — they can run entirely on-premise, in your own Kubernetes/OpenShift, on a VM, or fully air-gapped, so production answers need not leave the building. Account and gateway data for the hosted service is stored in Australia (AWS Sydney region). Data-residency options for US and other regions are available for enterprise engagements — talk to us about your requirement.
The hosted service uses a small set of vetted providers, each independently certified to recognised standards: Amazon Web Services (compute & database, SOC 2 / ISO 27001), Cloudflare (web hosting/CDN & edge, SOC 2 / ISO 27001), Stripe (payments, PCI-DSS Level 1), and Resend (transactional email). A current sub-processor list and a Data Processing Addendum (DPA) are available on request.
If you believe you have found a security vulnerability, please report it privately to info@verificate.ai with the subject “Security”. We will acknowledge your report, work with you on a fix, and credit you if you wish. Please do not publicly disclose until we have remediated.
Verificate handles personal information under the Australian Privacy Act 1988 (Cth) / Australian Privacy Principles, the EU/UK GDPR, and the California CCPA/CPRA where applicable. A Data Processing Addendum is available for enterprise customers. Payment processing is handled by a PCI-DSS Level 1 provider. The Verificate Gate additionally scores AI-written code against ISO/IEC 5055 and ISO/IEC 25010 — a product capability, distinct from the organisational control frameworks above. See our Privacy Policy and Legal & claims pages.
© 2026 Verificate Pty Ltd · ACN 681 762 818 · Sydney, NSW, Australia · Last updated 6 September 2026