Security

Overview

Security is fundamental to how Verumate is designed, built, and operated.

Verumate helps organizations analyze business data retrieved from authorized Connected Services. We recognize that Customers trust us with access to valuable business information, and we take that responsibility seriously.

Our security program is built around the principles of Security by Design, Privacy by Design, Least Privilege Access, and Customer Control.

This document provides an overview of the security measures we use to protect Customer Data and the Verumate platform.


Security Principles

Verumate follows these core security principles:

  • Security by Design

  • Privacy by Design

  • Read-only access by default

  • Least Privilege access

  • Customer control over Connected Services

  • Defense in depth

  • Encryption by default

  • Continuous monitoring

  • Responsible disclosure

  • Continuous improvement


Secure Authentication

Verumate supports secure authentication and authorization mechanisms designed to protect customer accounts and Connected Services.

Where supported, Connected Services are authorized using OAuth 2.0, allowing Customers to grant limited access without sharing passwords.

Verumate never stores passwords for Connected Services authorized through OAuth.

Customers remain in control of connected accounts and may revoke access at any time.


Encryption

Encryption in Transit

Communication between Customers, Connected Services, and Verumate is protected using HTTPS and Transport Layer Security (TLS).

Encryption in transit helps protect information from unauthorized interception while data is being transmitted.


Encryption at Rest

Sensitive information, including OAuth credentials and other confidential application data, is protected using appropriate encryption mechanisms while stored.

Where practical, sensitive data is encrypted before storage.


Access Controls

Access to systems and Customer Data is restricted according to the Principle of Least Privilege.

Verumate limits access based on operational responsibilities and business need.

Administrative access is restricted to authorized personnel responsible for operating and maintaining the platform.


Workspace Isolation

Each Customer Workspace is designed to operate independently.

Customer Data retrieved from one Workspace is not intentionally shared with another Workspace.

Verumate is designed to ensure that AI analyses, reports, and conversations are generated only from information available within the Customer’s own Workspace and authorized Connected Services.


Read-Only Access

Verumate is designed around a read-only access model wherever supported by Connected Services.

By default, Verumate:

  • retrieves authorized information;

  • analyzes business data;

  • generates reports;

  • provides evidence-backed recommendations; and

  • answers business questions.

Verumate does not modify customer data, campaigns, configurations, or settings within Connected Services unless a future feature explicitly requires Customer authorization and consent.


Infrastructure Security

Verumate is operated using industry-standard infrastructure security practices designed to protect the availability, confidentiality, and integrity of the Services.

Security measures may include:

  • Network segmentation

  • Firewall protections

  • Secure system configuration

  • Operating system updates

  • Vulnerability management

  • Infrastructure monitoring

  • Backup and recovery procedures

Infrastructure security practices continue to evolve as the platform grows.


Monitoring and Logging

Verumate maintains operational and security logs to help:

  • Detect unauthorized activity.

  • Monitor platform health.

  • Investigate security events.

  • Diagnose technical issues.

  • Improve service reliability.

Logs are retained only as necessary for operational, security, and compliance purposes in accordance with our Data Retention & Deletion Policy.


Incident Response

Verumate maintains procedures for identifying, investigating, responding to, and resolving security incidents.

Our incident response process includes:

  • Detection

  • Investigation

  • Containment

  • Remediation

  • Recovery

  • Post-incident review

Where appropriate, affected Customers will be notified in accordance with applicable legal and contractual obligations.


Business Continuity and Disaster Recovery

Verumate maintains backup and recovery procedures designed to support service continuity.

Our disaster recovery approach includes:

  • Encrypted backups

  • Recovery procedures

  • Infrastructure restoration

  • Operational resilience

  • Periodic review of recovery processes

Recovery procedures are intended to minimize service disruption while maintaining the integrity of Customer Data.


Secure Development

Security is considered throughout the software development lifecycle.

We continuously improve Verumate by:

  • Reviewing code changes.

  • Addressing security issues.

  • Updating software dependencies.

  • Improving platform resilience.

  • Monitoring emerging security risks.

As Verumate grows, our security practices will continue to mature alongside the platform.


Customer Responsibilities

Customers also play an important role in maintaining security.

Customers are responsible for:

  • Protecting account credentials.

  • Managing Authorized Users.

  • Securing Connected Services.

  • Reviewing Workspace permissions.

  • Reporting suspected security incidents promptly.


Responsible Disclosure

We appreciate responsible reporting of potential security vulnerabilities.

If you believe you have identified a security issue affecting Verumate, please contact us before publicly disclosing the issue so that we have an opportunity to investigate and resolve it.

Please include sufficient information to help us reproduce and understand the reported issue.


Continuous Improvement

Security is an ongoing process.

Verumate regularly reviews and improves its security practices to address evolving technologies, customer needs, and emerging threats.

As the platform evolves, additional security controls, certifications, and compliance programs may be introduced.


Contact

If you have questions about Verumate’s security practices or wish to report a potential security issue, please contact us:

Support Team

Email: support@verumate.com

For additional information, please refer to our Privacy Policy, Google API Data Usage & Limited Use Compliance, and Data Retention & Deletion Policy.