Skip to main content

Trust / terms

Clear terms for accountable use.

These terms govern access to Veriom’s website, platform, APIs, integrations, analysis, reports, and related services.

Effective date
Effective April 7, 2026
Version
Version 2026-04-07
Jurisdiction
Contract and applicable law

01. Acceptance and authority

Using the service means accepting these terms and confirming that you can enter the agreement.

Agreement

These terms form the agreement between Veriom and the person or organisation using the service. If you do not agree, you must not access or use the service.

Authority

You confirm that you are at least 18, have authority to act for the relevant organisation, and will use the service in accordance with applicable law.

Related policies

  • The Privacy Policy governs personal-data processing.
  • The Data Processing Agreement applies where agreed or required for eligible EU and UK processing.
  • An order form, deployment addendum, or data-residency schedule may add service-specific terms.

02. Service description

Veriom connects technical evidence to architectural causes, system consequences, and reviewable next actions.

  • Authorised evidence collection from repositories, cloud platforms, containers, CI/CD systems, uploads, and approved tools.
  • Architecture and security analysis, structural weakness detection, compliance context, and reporting.
  • AI-assisted insights and remediation guidance grounded in selected evidence.
  • Managed or enterprise services described in the applicable order.

Read-only evidence access

Evidence integrations are configured for read-only access. Where the product offers remediation or pull-request assistance, it requires separate scoped authorisation and explicit human approval before a change is proposed or created.

Service changes

The service may evolve. We will provide reasonable notice when a planned change materially reduces contracted core functionality.

03. Accounts and access

Customers are responsible for accurate registration, secure credentials, and correct workspace membership.

  • Keep passwords, API keys, tokens, and recovery material confidential.
  • Use appropriate access controls and multi-factor authentication where available.
  • Remove users who no longer need access and revoke compromised credentials immediately.
  • Organisations are responsible for the users and activity they authorise.

04. Acceptable use

Use Veriom only for lawful work on systems and information you are authorised to review.

You must not

  • Access, monitor, probe, or test a system without the owner’s permission.
  • Bypass access controls, security measures, usage limits, or approved APIs.
  • Introduce malware, harmful code, unlawful content, or deceptive activity.
  • Reverse engineer protected service code except where applicable law expressly permits it.
  • Resell, sublicense, or use the service to build a competing product without written permission.
  • Infringe intellectual property, privacy, employment, export-control, or data-protection obligations.

Your security responsibility

You remain responsible for securing your systems and deciding whether and how to implement a recommendation. Veriom’s output supports professional judgment; it does not guarantee that a system is complete, compliant, or secure.

05. API access and integrations

API and integration access must use valid credentials, appropriate scopes, and lawful source permissions.

  • Store integration credentials securely and rotate or revoke them when risk changes.
  • Configure only the permissions required for the intended review.
  • Follow the connected provider’s terms and maintain authority over submitted data.
  • Respect reasonable ingestion, API, storage, and concurrency limits communicated for the service.

06. Data and privacy

Customers retain ownership of Customer Data and grant Veriom the limited rights needed to deliver the service.

Processing scope

The service analyses authorised metadata, configurations, source patterns, and technical evidence. It is not intended to ingest customer business records, production payloads, secrets, or unrelated personal content.

Protection and isolation

Customer Data is protected through encryption, workspace-scoped controls, tenant isolation, and audit logging. Retention and residency depend on the selected service, region, and agreement.

Model processing

When models assist with reports, insights, or remediation guidance, Veriom selects and sanitises context before provider processing. The active provider configuration and agreement control provider-side retention and location.

Portability

On a verified request, available Customer Data can be exported in a commonly usable format where technically feasible and legally permitted.

07. Intellectual property

Veriom owns the service and its protected methods; customers keep their data and receive a limited right to use the service.

  • The subscription grants a limited, non-exclusive, non-transferable right for internal business use.
  • You may not copy, sell, lease, sublicense, remove notices from, or create unauthorised derivatives of the service.
  • Feedback may be used to improve the service without an obligation to compensate the contributor.
  • Anonymised and aggregated service information may be used for reliability, research, and benchmarking when it does not identify a customer.

08. Fees and payment

Charges, billing frequency, usage limits, and renewal terms are defined by the applicable order or plan.

Unless an order says otherwise, fees are payable in advance, exclude applicable taxes, and are non-refundable except where these terms expressly provide a remedy. Overdue amounts may lead to interest, collection activity, or service suspension after notice.

09. Confidentiality

Each party must protect the other party’s non-public information with reasonable care.

Confidentiality obligations do not cover information that was lawfully public, received without restriction, independently developed, or required to be disclosed by law. A legally compelled recipient should provide notice where permitted.

10. Warranties and disclaimers

Each party confirms it can enter the agreement. Other warranties are limited to those expressly stated.

Except for an express commitment in an order or these terms, the service is provided as available without implied warranties of merchantability, fitness, non-infringement, uninterrupted operation, result accuracy, or absolute security.

Veriom is not responsible for third-party systems or for a customer’s decision to implement, delay, or reject a recommendation.

11. Limitation of liability

Liability is limited to the extent permitted by law and allocated according to the commercial agreement.

Neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive loss, including lost profit, revenue, opportunity, goodwill, or business interruption, where the law allows that exclusion.

Veriom’s aggregate liability is capped at the greater of fees paid during the twelve months before the claim or GBP £10,000, except where applicable law or an agreed order does not permit that limitation.

Nothing excludes liability that cannot lawfully be limited, including applicable liability for fraud, gross negligence, or wilful misconduct.

12. Indemnification

Each party covers defined third-party claims caused by matters within its control, subject to notice and defence procedures.

Customers are responsible for claims arising from unlawful use, Customer Data, their systems, or their breach of these terms. Veriom will address qualifying claims that the service infringes third-party intellectual property, subject to prompt notice, cooperation, and control of the defence.

13. Term, suspension, and termination

Subscription duration and renewal follow the order. Material breach, security risk, fraud, or overdue payment may justify suspension or termination.

After termination, service access ends and customers should export required data within the available transition window. Unless another agreement applies, retained Customer Data is scheduled for deletion after 90 days, subject to backup expiry and legal retention.

14. Compliance

Both parties must follow applicable laws, including data-protection, sanctions, and export-control requirements.

You confirm that you are not prohibited from receiving the service and will not use it in an embargoed location or for a restricted purpose. Industry-specific compliance remains the customer’s responsibility unless expressly included in an order.

15. Third-party services

Authorised integrations and providers remain governed by their own availability, security, and terms.

Veriom is not responsible for an external provider’s outage, security incident, changed API, or independent processing. Current provider and licensing information is available through the platform’s trust and provider pages.

16. Changes to these terms

Material changes will be posted and communicated with reasonable notice before taking effect.

Non-material clarifications may apply when published. Continued use after an effective date indicates acceptance, subject to any termination right stated in the customer’s order or required by law.

17. Dispute resolution

The parties should first attempt good-faith resolution before starting formal proceedings.

Unless an order specifies another forum, England and Wales law and the courts of London apply to EU and UK customer disputes; Delaware law and courts apply to US customer disputes. Claims must be brought individually where a class-action waiver is enforceable.

18. General provisions

These terms and incorporated documents form the agreement and remain effective even if one provision is unenforceable.

  • Assignment requires consent, except for permitted affiliate or corporate-successor transfers.
  • Failure to enforce a provision is not a waiver; a waiver must be in writing.
  • Neither party is responsible for delay caused by events reasonably outside its control.
  • The parties are independent contractors and do not create a partnership or employment relationship.
  • Notices to Veriom should be sent to legal@veriom.io.
  • The English version controls if a translation differs.

19. Contact information

Contact the appropriate team for service, legal, or security matters.

  • General enquiries: support@veriom.io
  • Legal notices: legal@veriom.io
  • Security reports: security@veriom.io
Clear terms for accountable use. | veriom.