Trust / privacy
Privacy, without the small-print maze.
This policy explains the personal, operational, and system information Veriom processes; why it is needed; where model processing fits; and the choices available to you.
- Effective date
- Effective May 13, 2025
- Version
- Version 2025-05-13
- Jurisdiction
- Contract and applicable law
01. Information we collect
We collect the minimum account, usage, and authorised system information needed to operate and secure the service.
Personal and account information
- Contact details such as your name, business email address, and telephone number when supplied.
- Account identifiers and authentication information used to protect access.
- Messages, support requests, feedback, and other content you deliberately send to us.
Website and product usage
- Device, browser, operating system, approximate network, and security log information.
- Page visits, feature interactions, session state, reliability events, and consent choices.
- Essential cookies and, where you consent, limited analytics or preference cookies.
Authorised system evidence
- Repository metadata, dependency manifests, configuration, and contributor information within the scope you connect.
- Cloud configuration, identity policy, resource metadata, and access-log evidence made available by approved integrations.
- Security observations, delivery metadata, architecture relationships, and compliance evidence required for a review.
Evidence collection integrations are read-only. A remediation action uses a separate, explicitly approved scope and remains under human control.
02. How we use information
Information is used to deliver reviews, protect accounts, communicate with users, and improve service reliability.
- Authenticate users and enforce workspace, membership, and integration permissions.
- Identify security and architecture risks, trace contributing causes, and produce reviewable recommendations.
- Respond to enquiries, deliver requested product messages, and send relevant security or service notifications.
- Measure reliability, diagnose failures, prevent abuse, and understand consented website usage.
- Meet contractual, legal, accounting, security, and regulatory obligations.
03. How we protect data
Controls are designed around encryption, tenant isolation, least privilege, auditability, and bounded execution.
- Encryption protects data in transit and encrypted service artifacts at rest.
- Role-based access, workspace-scoped authorisation, and database isolation limit who and what can retrieve data.
- Administrative actions, model usage, and material review activity are recorded for audit and investigation.
- Security monitoring, dependency review, and incident procedures support detection and response.
Veriom maps controls to ISO 27001 and SOC 2 readiness criteria. Alignment is not a claim of certification or a completed independent assessment.
04. Cookies and analytics
Essential cookies keep sessions secure. Optional analytics remain off until the relevant consent is recorded.
- Essential cookies support authentication, security, routing, and saved consent choices.
- Preference cookies remember settings you ask the website to retain.
- Analytics cookies help us understand public-site usage only after consent where required.
- Product evidence, source content, findings, secrets, prompts, and reports are excluded from website analytics.
05. Where data is processed
The selected service region and the providers used for a workspace determine where processing occurs.
European hosting is the default service posture. Where an agreed deployment or provider requires another region, the applicable order, data-processing terms, and transfer safeguards control that processing.
A requested residency option does not override essential provider routing or legal-transfer terms unless it is confirmed in writing.
06. Sharing and service providers
We do not sell personal information. Limited providers process data only to help operate the service or satisfy a lawful requirement.
- Infrastructure, communications, identity, security, and model providers supporting contracted service delivery.
- Professional advisers and authorities where disclosure is required by law or necessary to protect rights and safety.
- A successor organisation in a merger, financing, acquisition, or asset transfer, subject to applicable safeguards.
07. AI-assisted processing
Models receive selected context for a defined job; they do not receive unrestricted access to your workspace.
Veriom can send bounded and redacted evidence to a configured model provider to help produce architecture, security, report, or remediation artifacts. Provider choice, retention configuration, and the applicable agreement determine the provider-side processing terms.
Veriom keeps final structured artifacts and measured usage needed to operate the product. Hidden reasoning is not presented as evidence, and consequential actions remain subject to explicit approval.
08. Retention and deletion
Retention follows data class, workspace policy, contractual need, security requirements, and provider expiry windows.
When a workspace is deleted, Veriom starts an auditable lifecycle covering tenant records, encrypted objects, vectors, reports, and credentials. Backups, fraud-prevention records, financial records, and provider logs may remain until their documented expiry or a legal requirement ends.
09. Your privacy rights
Depending on your location, you may request access, correction, deletion, restriction, objection, or portability.
We may need to verify your identity, authority, and workspace relationship before completing a request. Some records may be retained where law, security, or the rights of another person require it.
10. Contact us
Use the dedicated addresses below for privacy, security, and support requests.
- Privacy and security: security@veriom.io
- General support: support@veriom.io
- Contractual and data-processing questions: legal@veriom.io