Skip to content
Verificate
Trust · Security

Trust & Security

Security and sovereignty are the product. Verificate is engineered so that sensitive data and decisions stay inside your boundary. This Trust Center documents our controls, mapped to the AICPA SOC 2 Trust Services Criteria and an ISO/IEC 27001:2022 control framework — stated accurately, the way an enterprise security team would want to verify them.

Certification status — stated plainly

We publish our security posture the way an enterprise security team would want to verify it — accurately.

SOC 2 R

Controls designed and mapped to the AICPA Trust Services Criteria; a SOC 2 Type II examination is on our roadmap. We do not represent a completed attestation until a report is issued; audit status and any report are available under NDA.

ISO/IEC 27001:2022 R

Information security managed under an ISO/IEC 27001:2022 control framework, evidence-based and independently reviewed as controls mature; formal certification is on our roadmap. We do not claim certification until an accredited certificate is issued.

Our hosted service runs on AWS (Sydney region) and Cloudflare — infrastructure that is itself independently certified to SOC 2 and ISO/IEC 27001 — and our products can run entirely inside your own boundary, on-premises or air-gapped, so the most sensitive data need never leave the building.

SOC 2 Trust Services Criteria

Our controls address each of the five criteria:

Security (Common Criteria)
  • —TLS encryption in transit on all endpoints (edge-terminated).
  • —Passwords stored only as one-way bcrypt hashes; short-lived signed (JWT) sessions.
  • —Single-user API keys — per-key rate limiting and automated key-sharing (multi-IP) detection block abuse.
  • —Least-privilege access; secrets held in the platform secret store, never in source.
  • —No anonymous access to metered endpoints; the raw model routes are not publicly exposed.
Availability
  • —Runs on managed OpenShift with health-checked, restartable workloads and a durable, backed-up database.
  • —Website served via a global CDN (Cloudflare) with static, cacheable assets.
  • —Capacity and error monitoring; graceful degradation (e.g. maintenance responses) rather than hard failure.
Processing Integrity
  • —Bit-exact C++/ONNX inference — 0 / 10,000 argmax mismatches vs the reference.
  • —Deterministic decisioning with per-decision audit lineage.
  • —Governed proposal layer: changes are validated and gated before they can affect a live decision.
Confidentiality
  • —Data classification and access control; sensitive reports shared only under NDA.
  • —Sovereign, zero-egress product architecture — raw data never leaves the customer boundary.
  • —Tenant isolation; dedicated database for account and usage data.
Privacy
  • —Data minimisation and purpose limitation; cookie-free, first-party analytics with no third-party trackers.
  • —Data-subject rights honoured under the Privacy Act 1988 and GDPR.
  • —See our Privacy Policy for the full detail.

ISO/IEC 27001:2022 control framework

Information security is managed under an ISO/IEC 27001:2022 control framework — a documented control matrix mapped to Annex A, operated on evidence and independently reviewed as each control matures. Coverage spans the four Annex A themes:

Organizational controls

Information-security policies, asset & access management, supplier and cloud-service security, classification, incident management and continuity (A.5).

People controls

Screening, security responsibilities, awareness and access on joining, changing and leaving (A.6).

Physical controls

Secure facilities and equipment for the managed-cloud substrate; sovereign / air-gapped options remove the surface entirely (A.7).

Technological controls

Cryptography, secure development (SDLC), logging & monitoring, vulnerability & threat management, data masking, backup and secure configuration (A.8).

A control is recorded as operating only when a named owner has attached current evidence and an independent reviewer has accepted it. Certification is on our roadmap; we do not claim it until an accredited certificate is issued.

Data residency & sovereignty

Verificate products are CPU-native and architected for zero network egress — they can run entirely on-premise, in your own Kubernetes/OpenShift, on a VM, or fully air-gapped, so production answers need not leave the building. Account and gateway data for the hosted service is stored in Australia (AWS Sydney region). Data-residency options for US and other regions are available for enterprise engagements — talk to us about your requirement.

Sub-processors

The hosted service uses a small set of vetted providers, each independently certified to recognised standards: Amazon Web Services (compute & database, SOC 2 / ISO 27001), Cloudflare (web hosting/CDN & edge, SOC 2 / ISO 27001), Stripe (payments, PCI-DSS Level 1), and Resend (transactional email). A current sub-processor list and a Data Processing Addendum (DPA) are available on request.

Responsible disclosure

If you believe you have found a security vulnerability, please report it privately to info@verificate.ai with the subject “Security”. We will acknowledge your report, work with you on a fix, and credit you if you wish. Please do not publicly disclose until we have remediated.

Privacy & regulatory

Verificate handles personal information under the Australian Privacy Act 1988 (Cth) / Australian Privacy Principles, the EU/UK GDPR, and the California CCPA/CPRA where applicable. A Data Processing Addendum is available for enterprise customers. Payment processing is handled by a PCI-DSS Level 1 provider. The Verificate Gate additionally scores AI-written code against ISO/IEC 5055 and ISO/IEC 25010 — a product capability, distinct from the organisational control frameworks above. See our Privacy Policy and Legal & claims pages.

© 2026 Verificate Pty Ltd · ACN 681 762 818 · Sydney, NSW, Australia · Last updated 6 September 2026