Security
Overview
Security is fundamental to how Verumate is designed, built, and operated.
Verumate helps organizations analyze business data retrieved from authorized Connected Services. We recognize that Customers trust us with access to valuable business information, and we take that responsibility seriously.
Our security program is built around the principles of Security by Design, Privacy by Design, Least Privilege Access, and Customer Control.
This document provides an overview of the security measures we use to protect Customer Data and the Verumate platform.
Security Principles
Verumate follows these core security principles:
Security by Design
Privacy by Design
Read-only access by default
Least Privilege access
Customer control over Connected Services
Defense in depth
Encryption by default
Continuous monitoring
Responsible disclosure
Continuous improvement
Secure Authentication
Verumate supports secure authentication and authorization mechanisms designed to protect customer accounts and Connected Services.
Where supported, Connected Services are authorized using OAuth 2.0, allowing Customers to grant limited access without sharing passwords.
Verumate never stores passwords for Connected Services authorized through OAuth.
Customers remain in control of connected accounts and may revoke access at any time.
Encryption
Encryption in Transit
Communication between Customers, Connected Services, and Verumate is protected using HTTPS and Transport Layer Security (TLS).
Encryption in transit helps protect information from unauthorized interception while data is being transmitted.
Encryption at Rest
Sensitive information, including OAuth credentials and other confidential application data, is protected using appropriate encryption mechanisms while stored.
Where practical, sensitive data is encrypted before storage.
Access Controls
Access to systems and Customer Data is restricted according to the Principle of Least Privilege.
Verumate limits access based on operational responsibilities and business need.
Administrative access is restricted to authorized personnel responsible for operating and maintaining the platform.
Workspace Isolation
Each Customer Workspace is designed to operate independently.
Customer Data retrieved from one Workspace is not intentionally shared with another Workspace.
Verumate is designed to ensure that AI analyses, reports, and conversations are generated only from information available within the Customer’s own Workspace and authorized Connected Services.
Read-Only Access
Verumate is designed around a read-only access model wherever supported by Connected Services.
By default, Verumate:
retrieves authorized information;
analyzes business data;
generates reports;
provides evidence-backed recommendations; and
answers business questions.
Verumate does not modify customer data, campaigns, configurations, or settings within Connected Services unless a future feature explicitly requires Customer authorization and consent.
Infrastructure Security
Verumate is operated using industry-standard infrastructure security practices designed to protect the availability, confidentiality, and integrity of the Services.
Security measures may include:
Network segmentation
Firewall protections
Secure system configuration
Operating system updates
Vulnerability management
Infrastructure monitoring
Backup and recovery procedures
Infrastructure security practices continue to evolve as the platform grows.
Monitoring and Logging
Verumate maintains operational and security logs to help:
Detect unauthorized activity.
Monitor platform health.
Investigate security events.
Diagnose technical issues.
Improve service reliability.
Logs are retained only as necessary for operational, security, and compliance purposes in accordance with our Data Retention & Deletion Policy.
Incident Response
Verumate maintains procedures for identifying, investigating, responding to, and resolving security incidents.
Our incident response process includes:
Detection
Investigation
Containment
Remediation
Recovery
Post-incident review
Where appropriate, affected Customers will be notified in accordance with applicable legal and contractual obligations.
Business Continuity and Disaster Recovery
Verumate maintains backup and recovery procedures designed to support service continuity.
Our disaster recovery approach includes:
Encrypted backups
Recovery procedures
Infrastructure restoration
Operational resilience
Periodic review of recovery processes
Recovery procedures are intended to minimize service disruption while maintaining the integrity of Customer Data.
Secure Development
Security is considered throughout the software development lifecycle.
We continuously improve Verumate by:
Reviewing code changes.
Addressing security issues.
Updating software dependencies.
Improving platform resilience.
Monitoring emerging security risks.
As Verumate grows, our security practices will continue to mature alongside the platform.
Customer Responsibilities
Customers also play an important role in maintaining security.
Customers are responsible for:
Protecting account credentials.
Managing Authorized Users.
Securing Connected Services.
Reviewing Workspace permissions.
Reporting suspected security incidents promptly.
Responsible Disclosure
We appreciate responsible reporting of potential security vulnerabilities.
If you believe you have identified a security issue affecting Verumate, please contact us before publicly disclosing the issue so that we have an opportunity to investigate and resolve it.
Please include sufficient information to help us reproduce and understand the reported issue.
Continuous Improvement
Security is an ongoing process.
Verumate regularly reviews and improves its security practices to address evolving technologies, customer needs, and emerging threats.
As the platform evolves, additional security controls, certifications, and compliance programs may be introduced.
Contact
If you have questions about Verumate’s security practices or wish to report a potential security issue, please contact us:
Support Team
Email: support@verumate.com
For additional information, please refer to our Privacy Policy, Google API Data Usage & Limited Use Compliance, and Data Retention & Deletion Policy.
