verity

Security at Verity

Built like the controls it tracks.

You trust Verity with the evidence that proves your organisation keeps its promises. These are the properties the platform is built around, written plainly so your security and procurement teams can check them.

Audit log
Append-only
  • Dana Okafor approved evidenceQ3 access review sign-off
  • Ayesha Raza changed control statusIAM-02 · In progress → Implemented
  • Omar Haddad accepted a risk until 31 MarLegacy VPN appliance
  • Sofia Martins decided a vendorHarbor Cloud Hosting · Approved with conditions

Sample entries · before and after kept for each

How the platform protects you

Six properties, and how each one holds.

Workspace isolation

  • Every workspace is sealed by the database itself, on every query, not by the interface.
  • A person in two organisations sees one at a time; no screen, filter or export shows two workspaces together.
  • Automated isolation tests run on every change to prove one workspace cannot read another.

Access control

  • Six built-in roles, groups and granular permissions for each module and action.
  • Two-factor sign-in can be required for administrators; passwords need 12 characters with mixed case, a digit and a symbol by default.
  • External auditors and consultants get access windows that close on their own.
  • Leavers are disabled, not deleted, so their approvals and evidence stay attributable.

A history you can trust

  • Every state-changing action writes who, when, and the record before and after.
  • The audit log is append-only, enforced by the database: nobody can edit or delete it, administrators included.
  • Controls, risks, documents and vendors are retired with a recorded reason, never deleted.

Secrets and connections

  • Connection tokens and two-factor secrets are encrypted in the application before they reach the database, and never written to logs.
  • Connections ask for read-only, least-privilege access. Disconnecting destroys the token; the history stays.
  • A broken connection is reported as an error, never as a failed control.

Evidence handling

  • Evidence files are kept in object storage, not in the database.
  • A file you upload cannot change underneath you, which is what an auditor needs.
  • Evidence carries renewal dates, so stale proof is visible.

AI governance

  • AI drafts and suggests; a person approves, publishes and decides.
  • AI content is marked as an AI draft and goes through the same approval as anything a person writes.
  • If an AI provider is unavailable, you can always do the work by hand.
Coming soonComing next: single sign-on through your identity provider, periodic access reviews, and read-only auditor access scoped to an engagement.Read the roadmap pages

Common questions

Security questions.

If your procurement team has a questionnaire, send it to us.

Is Verity SOC 2 or ISO 27001 certified?
We do not claim certifications on this site. If your procurement process needs our security documentation, talk to our team and we will tell you what is available and when.
Where is our data hosted?
Talk to our team about hosting and data-residency requirements, especially if you are a regulated institution with in-country obligations.
Can our auditor see our workspace?
Yes. Invite them with an access window: they can sign in between the dates you set, with the role you choose, and every action they take is in the audit log.
Do you support single sign-on?
Single sign-on through your identity provider is coming soon. Today Verity uses email and password sign-in, with two-factor authentication that you can require for administrators.

Bring your security questionnaire.

We will walk your team through how Verity protects the evidence you keep with us.