Trust & Security Center

Don't take our word for it. Check ours.

Our security posture is verified automatically against the live deployment and timestamped on every run — we publish only what the collector confirms, never a hand-set status.

Continuously verified · last collector run 44 min ago
All systems verified
5 of 5 controls passing
100%
Uptime 90d
100%
Core data in EU
0
Open incidents
EU data residency Encrypted at rest & in transit GDPR-native Hash-sealed evidence Core data hosted in the EU

Live security posture

Auto-checked · each item timestamped
Clickjacking protection
enforced · X-Frame-Options: DENY
Verified 44 min ago · 2026-09-10 17:00 UTC
Verified
Content Security Policy
enforced · 9 directives
Verified 44 min ago · 2026-09-10 17:00 UTC
Verified
Application liveness
healthy · db connected · 95ms round-trip
Verified 44 min ago · 2026-09-10 17:00 UTC
Verified
HTTP Strict Transport Security
enforced · max-age 730d
Verified 44 min ago · 2026-09-10 17:00 UTC
Verified
TLS certificate
valid · 55 days to renewal
Verified 44 min ago · 2026-09-10 17:00 UTC
Verified

EU data residency

Where every byte lives
Application hostingHetzner CPX32 (Nuremberg, Germany)EU
DatabasePostgreSQL on Hetzner (Nuremberg, Germany)EU
File storageHetzner Object Storage (Falkenstein, Germany)EU
AI processingMistral AI (Paris, France)EU
Rate-limit storeUpstash Redis (AWS eu-central-1, Frankfurt)EU
Error monitoringSentry EU region (Germany)EU
Product analyticsPostHog EU Cloud (Frankfurt)EU
Transactional emailResend (San Francisco, USA)SCCs
Payment processingStripe (Dublin, Ireland · PCI DSS L1)SCCs
Sign-in & analyticsGoogle (Ireland · USA)SCCs
Sign-in (Entra ID)Microsoft (Ireland · USA)SCCs
Evidence connectorGitHub (USA) — opt-inSCCs
Evidence connectorAtlassian Jira (USA) — opt-inSCCs
AI training useContractually excluded
Supervisory authorityIrish DPC

Compliance & certifications

Status, honestly
Preparing

Cyber Resilience Act

SBOM + vuln-disclosure live; CRA obligations phasing in
Compliant

GDPR

Reg. (EU) 2016/679 · DPA, DSAR, breach process
Planned

ISO 27001

Controls foundation in progress · target 2026
Planned

ISO 42001

AI management system — our differentiator

Request the full security report

Our architecture review, control descriptions and sub-processor detail are shared under NDA. We have not yet completed an external penetration test or a third-party audit; when we do, the report will be available here. detailed architecture review are shared under NDA. Enter your work email and accept the non-disclosure terms to receive the full report.

Policies & documents

Enterprise security inquiries

For security questionnaires or custom DPA negotiations, contact security@veritome.eu