Security
Security practices for organizations that depend on mission-critical software.
Verion designs systems with structured access, traceable workflows, and privacy-conscious practices. This page describes our general approach - specific deployment details are discussed during implementation.
Designed for cloud-native deployments with isolated environments and controlled network access.
Built with TLS in transit and strong encryption practices at rest for supported deployments.
Authentication is designed for strong practices such as multi-factor authentication, SSO, and configurable session policies where those controls are enabled for a given deployment. Availability of MFA/SSO depends on the product stage and customer deployment - confirm during onboarding rather than assuming every option is generally available today.
Role-based access control with team-scoped permissions and principle of least privilege.
Privacy-conscious design with PDPA considerations. Data processing agreements available for enterprise clients.
Verion does not currently claim SOC 2, ISO 27001, GDPR, or PDPA certification. We design controls with those frameworks in mind and discuss deployment-specific requirements during onboarding.
Backup and recovery practices are defined per deployment, including retention and geography as agreed.
Documented incident response procedures with defined escalation paths and customer notification protocols.
Reach Verion at hello@verion.one for vulnerability reports and security inquiries.
We welcome responsible disclosure of security vulnerabilities. Reports are acknowledged within 48 hours.
Availability targets and public status monitoring will be published when production services are launched.
Report security vulnerabilities to our security team.