Trust and governance
How VERION products handle control, permissions, approvals, auditability, data isolation, security and privacy. This page describes our general approach; deployment specifics are agreed in the customer agreement.
VEDA prepares work and proposes actions. Anything consequential waits for an authorized person, and the product records who approved it.
Role-based access designed around teams and responsibilities, with least-privilege roles and organization scope.
Approval steps attach to the work itself, with explicit pending, in-review and completed states.
Prepared, reviewed and completed steps remain visible in activity history for review and accountability.
Each organization's data is scoped to that organization and to the roles within it.
TLS in transit and encryption practices at rest for supported deployments; controlled network access and isolated environments.
Privacy-conscious design with Thailand's PDPA in mind. Data processing agreements are available for enterprise customers.
Backup and recovery practices are defined per deployment. Availability targets and public status monitoring will be published as production services expand.
VERION does not currently hold SOC 2, ISO 27001, GDPR or PDPA certification. We design controls with those frameworks in mind and discuss deployment-specific requirements during onboarding. We will state certifications here only when we hold them.
Designed for cloud-native deployments with isolated environments and controlled network access.
Built with TLS in transit and strong encryption practices at rest for supported deployments.
Authentication is designed for strong practices such as multi-factor authentication, SSO, and configurable session policies where those controls are enabled for a given deployment. Availability of MFA/SSO depends on the product stage and customer deployment - confirm during onboarding rather than assuming every option is generally available today.
Role-based access control with team-scoped permissions and principle of least privilege.
Privacy-conscious design with PDPA considerations. Data processing agreements available for enterprise clients.
Backup and recovery practices are defined per deployment, including retention and geography as agreed.
We maintain internal incident response and escalation practices. Formal notification commitments, including timelines, are agreed per deployment in the customer agreement rather than promised sitewide.
Availability targets and public status monitoring will be published when production services are launched.
We welcome responsible disclosure of security vulnerabilities. Send reports to hello@verion.one. We aim to acknowledge them within two business days and will tell you how we plan to handle the issue.