Security

We handle your most sensitive security artifacts. Here's how we protect them.

VerityOps stores your SOC 2 reports, security policies, pen test summaries, and questionnaire responses. We take that responsibility seriously — and we back it with the same standards your buyers demand of you.

SOC 2 Type II (In Progress)

VerityOps is pursuing SOC 2 Type II certification covering security, availability, and confidentiality. Our controls are being built to satisfy Type II requirements. We'll share our report through our own Portal when the audit is complete.

Encryption

All data encrypted at rest (AES-256) and in transit (TLS 1.2+). Encryption keys are managed through a dedicated key management service.

Access controls

Role-based access control throughout the platform. Your data is isolated per workspace. Our internal access follows least-privilege principles with audit logging.

Infrastructure

Hosted on SOC 2-certified cloud infrastructure. Automated vulnerability scanning. Regular third-party penetration testing.

Data handling

Your evidence documents and questionnaire responses are used only to serve your account. We do not use customer data to train models. You can export or delete your data at any time.

Incident response

Documented incident response plan with defined escalation procedures and customer notification commitments.

Want the full picture?

Visit our Portal for our SOC 2 report, security policies, subprocessor list, and more.

Join early access →