Trust & Security Centre

Don't take our word for it. Check ours.

Our security posture is verified automatically against the live deployment and timestamped on every run — we publish only what the collector confirms, never a hand-set status.

Continuously verified · last collector run 10 min ago
All systems verified
5 of 5 controls passing
100%
Uptime 90d
100%
Core data in EU
0
Open incidents
EU data residency Encrypted at rest and in transit GDPR-native Hash-sealed evidence Core data hosted in the EU

Live security posture

Auto-checked · each item timestamped
Clickjacking protection
enforced · X-Frame-Options: DENY
Verified 10 min ago · 2026-09-22 05:00 UTC
Verified
Content Security Policy
enforced · 9 directives
Verified 10 min ago · 2026-09-22 05:00 UTC
Verified
Application liveness
healthy · db connected · 59ms round-trip
Verified 10 min ago · 2026-09-22 05:00 UTC
Verified
HTTP Strict Transport Security
enforced · max-age 730d
Verified 10 min ago · 2026-09-22 05:00 UTC
Verified
TLS certificate
valid · 44 days to renewal
Verified 10 min ago · 2026-09-22 05:00 UTC
Verified

EU data residency

Where every byte lives
Application hostingHetzner (Nuremberg, Germany)EU
DatabaseHetzner (Nuremberg, Germany)EU
File storageHetzner Object Storage (Falkenstein, Germany)EU
AI processingMistral AI (Paris, France)EU
Rate-limit storeUpstash Redis (AWS eu-central-1, Frankfurt)EU
Error monitoringSentry EU region (Germany)EU
Product analyticsPostHog EU Cloud (Frankfurt)EU
Transactional emailPlunk on Hetzner (Germany, EU)EU
Payment processingStripe (Dublin, Ireland · PCI DSS L1)SCCs
Sign-in & analyticsGoogle (Ireland · USA)SCCs
Sign-in (Entra ID)Microsoft (Ireland · USA)SCCs
Evidence connectorGitHub (USA) — opt-inSCCs
Evidence connectorAtlassian Jira (USA) — opt-inSCCs
AI training useContractually excluded
Supervisory authorityIrish DPC

Compliance and certifications

Status, honestly
Preparing

Cyber Resilience Act

SBOM + vuln-disclosure live; CRA obligations phasing in
Compliant

GDPR

Reg. (EU) 2016/679 · DPA, DSAR, breach process
Planned

ISO 27001

Controls foundation in progress · target 2026
Planned

ISO 42001

AI management system — our differentiator
Under NDA

Request the full security report

Our architecture review, control descriptions and sub-processor detail are shared under NDA. We have not yet completed an external penetration test or a third-party audit; when we do, the report will be available here. Enter your work email and accept the non-disclosure terms to receive it.

Policies and documents

Enterprise security enquiries

For security questionnaires or custom DPA negotiations, contact security@veritome.eu