Skip to main content
Trust center / Legal

Data processing, written for scrutiny.

Veriom's standard Data Processing Agreement describes how customer data is handled across evidence ingestion, architecture analysis, security review, AI-assisted reasoning, and controlled remediation.

Bounded access

Workspace-scoped authorization and tenant isolation

Protected evidence

Encrypted transport, storage, and source snapshots

Governed AI

Selected context and agreed retention limits

Human authority

No consequential action without authorized confirmation

Contract note

This standard form becomes binding only when it is incorporated into an executed Veriom agreement or order form. The executed agreement identifies the legal entities, governing law, and any customer-specific terms. Customers should have counsel review the document before execution.

01

Scope and precedence

This DPA applies when Veriom processes Personal Data on behalf of Customer to provide the services described in an applicable order form or services agreement, together the Agreement.

If this DPA conflicts with the Agreement on the processing of Personal Data, this DPA controls. Customer-specific signed terms control over this public standard form.

02

Roles and instructions

Customer is the controller or business that determines why Personal Data is processed. Veriom acts as Customer's processor or service provider. Each party remains responsible for obligations that apply to its own role.

Veriom processes Personal Data only to provide, secure, support, and improve the contracted service according to the Agreement, Customer's documented configuration, and lawful written instructions.

03

Customer responsibilities

Customer will provide lawful instructions, maintain necessary notices and permissions, connect only repositories and sources it is authorized to review, and avoid submitting regulated data outside the agreed service scope.

Customer controls workspace membership, integration permissions, evidence retention settings, and approval of reports or remediation actions.

04

Provider obligations

Veriom will process data only for the documented purpose, limit personnel and service access to need, maintain appropriate technical and organizational measures, and notify Customer if an instruction appears to violate applicable data protection law.

Veriom will not sell Customer Personal Data or use it for targeted advertising. Customer workspace evidence is not published as marketing content.

05

Confidentiality

Personnel authorized to process Customer Data are bound by confidentiality obligations and receive access according to role and service purpose. Confidentiality duties continue after access ends.

Repository source, findings, architecture relationships, prompts, reports, and remediation artifacts are treated as confidential service data.

06

Security measures

Veriom maintains the measures described in Annex II. They include tenant-scoped authorization, row-level database controls, encrypted transport, protected object storage, per-workspace source encryption, expiring credentials, bounded model context, audit events, and controlled workers.

Security measures evolve with risk and the service. Veriom will not materially reduce the overall protection of Customer Data during an active Agreement.

07

AI processing

Models receive selected, bounded evidence needed for a task, not unrestricted access to the workspace. Processing remains subject to the agreed data-protection and retention terms.

Veriom does not use Customer Data to train its own general-purpose models. Downstream provider handling remains subject to the contracted provider configuration and applicable provider terms. Veriom stores final structured artifacts and measured usage, not hidden model reasoning.

08

Subprocessors

Customer authorizes the subprocessors identified in the register provided with the applicable agreement to support the service. Veriom remains responsible for their processing to the extent required by applicable law and will impose data protection duties appropriate to their services.

Material changes to the register will be communicated through an agreed notice channel. Customer may raise a reasonable, documented data protection objection before the change takes effect.

09

Data subject requests

Taking into account the nature of processing, Veriom will provide reasonable assistance for access, correction, deletion, restriction, portability, or objection requests. If a request is received directly, Veriom will direct the requester to Customer unless law requires another response.

10

Security incidents

Veriom will notify Customer without undue delay after confirming a security incident affecting Customer Personal Data. Notice will include available information needed to understand the nature, likely impact, containment, and remediation, with updates as the investigation develops.

Unsuccessful attempts, routine scanning, and events that do not compromise Customer Personal Data are not security incidents under this section.

11

Deletion and return

During the service term, Customer can export supported reports and artifacts. On workspace deletion or termination, Veriom begins an auditable lifecycle covering tenant records, objects, vectors, reports, and credentials, subject to configured retention, provider backup expiry, and legal obligations.

Data required to demonstrate security, billing, or legal compliance may be isolated and retained only for the applicable purpose and period.

12

International transfers

Where Personal Data is transferred across a legally protected boundary, the parties will use the transfer mechanism identified in the executed Agreement or order form, including applicable standard contractual clauses where required.

Processing locations and transfer safeguards are set out in the applicable agreement. Customer acknowledges that global delivery providers may process limited operational data outside the primary application region.

13

Audit support

On reasonable written request, Veriom will provide information needed to demonstrate compliance with this DPA, such as control descriptions, architecture boundaries, and relevant independent reports when available.

Additional audits must be proportionate, protect other customers and security-sensitive information, avoid unreasonable service disruption, and follow confidentiality and cost arrangements agreed by the parties. This page does not claim a certification Veriom has not obtained.

Annex I

Details of processing

Subject and purpose

Provide repository ingestion, security auditing, architecture intelligence, evidence-grounded assistant features, reports, and controlled remediation.

Duration

The Agreement term plus the configured retention and deletion lifecycle, unless law requires longer retention.

Data subjects

Customer users, team members, contractors, and individuals whose Personal Data appears in authorized repositories or evidence.

Data categories

Account and membership data, repository metadata and source evidence, findings, relationships, prompts, structured outputs, reports, usage, and cost records.

Processing operations

Collect, validate, encrypt, store, index, retrieve, analyze, reconcile, report, export, delete, and support.

Sensitive data

Not intentionally required. Customer should not submit special-category or highly regulated data unless expressly agreed.

Annex II

Technical and organizational measures

Identity and access

Workspace-scoped authorization, role checks, short-lived service credentials, audited administrative operations, and least-purpose access.

Encryption and secrets

TLS in transit, encrypted managed storage, per-workspace source data keys, authenticated encryption, and masked secrets in logs and evidence views.

Workload boundaries

Separated API, workflow, scanner, and worker responsibilities; archive validation; bounded tools; no platform credentials in untrusted execution contexts.

Model governance

Selected evidence, bounded permissions, human review, and agreed retention limits.

Auditability and recovery

Durable workflow events, idempotent operations, usage attribution, monitored failures, deletion records, and managed backup lifecycles.

Need a signed or customer-specific DPA?

Send your contracting entity, jurisdiction, and security questionnaire. We will route the request for review without asking you to restate the product context.

Data Processing Agreement | veriom.