Trust Center
Everything a buyer, an IT reviewer, or a curious customer needs to evaluate VERA, in one place. Each section summarizes a position and links to the document that states it in full. Where the honest answer is "not yet", this page says so, because a trust page that only lists strengths is not a trust page.
- Version
- 1.0
- Effective
- July 28, 2026
- Last updated
- July 28, 2026
- Revisions
- 1
On this page (9 sections)
1. At a glance
VERA is an AI business operations assistant for small businesses. It holds business records, customer data, connected platform credentials, and generated content on behalf of its customers.
| Question | Answer |
|---|---|
| Is data encrypted in transit? | Yes. HTTPS everywhere, with HSTS and an HTTP-to-HTTPS redirect in production. |
| Are credentials encrypted at rest? | Yes. AES-256-GCM with a dedicated key required in production. |
| Do you sell customer data? | No. Never, in any form. |
| Do you train AI models on customer data? | No. Prompts go to providers under commercial API terms that do not grant training rights on API inputs. |
| Can VERA act without approval? | No, unless you build an automation rule yourself. External actions are gated on approval in code. |
| Do you have SOC 2 or ISO 27001? | No. VERA holds no security certification today. |
| Do you offer MFA or SSO? | No. Google sign-in inherits your Google account's MFA; that is the strongest option available today. |
| Do you offer team accounts? | No. One business per account. Roles exist as a design model, not as enforced permissions. |
| Where is data processed? | United States. No regional hosting option. |
| Do you have an uptime SLA? | No. |
| Is there a DPA? | Yes, with Standard Contractual Clauses incorporated. It applies automatically. |
| Is there advertising or tracking? | No ad pixels, no marketing cookies, no cross-site tracking. |
2. Security
VERA's security model starts with the approval gate: the product does not take an external action on your behalf until you approve it or until an automation rule you built fires. Around that sit encrypted credential storage, hashed passwords, revocable sessions, tenant-scoped queries, durable rate limiting, signature-verified webhooks, protection against server-side request forgery, and hardened HTTP headers.
The Security Policy lists every implemented control and, in a section of equal length, every control that is not implemented yet, including multi-factor authentication, single sign-on, penetration testing, and certifications.
3. Privacy
VERA does not sell personal information, does not share it for advertising, runs no marketing or tracking cookies, and does not use customer data to train AI models. Analytics on the marketing site are limited to page and performance measurement plus a closed set of non-identifying event values.
For your own account data VERA is the controller; for your customers' data you are the controller and VERA is your processor. The Privacy Policy sets out the full inventory of what is collected and why, including an explicit list of the categories VERA does not collect.
4. Compliance
VERA offers a Data Processing Addendum that applies automatically on acceptance of the Terms of Service, incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers out of the EEA, UK, and Switzerland.
The GDPR Privacy Rights page and the California Privacy Notice describe how to exercise statutory rights, how we verify requests, and our response timelines. We apply the same request and appeal process to residents of other US states with comprehensive privacy laws rather than maintaining a separate procedure for each.
VERA holds no compliance certification. There is no SOC 2 report, no ISO 27001 certificate, no HIPAA business associate agreement, and no PCI DSS attestation for VERA itself, since card data is handled entirely by Stripe. If your procurement process requires an audit report, we can complete a security questionnaire in its place, as provided for in the Data Processing Addendum.
5. Infrastructure
VERA is a containerized Next.js application on Node.js, running against a managed PostgreSQL database, deployed on managed hosting in the United States. Uploaded files and generated images live in the application database rather than a separate object store, which removes an entire class of misconfigured-bucket exposure and keeps the data inventory small.
The full list of infrastructure and service providers, with what each receives, is on the Subprocessor List.
6. Availability
VERA does not offer a service level agreement or an uptime commitment, and does not currently publish a status page or incident history. The Service is provided on an as-available basis.
Background work such as scheduled posts and periodic syncs runs on an in-process scheduler. It executes only proposals that already carry an approved status, so a scheduling delay postpones an action rather than performing an unapproved one.
Features that depend on a third-party platform inherit that platform's availability. A provider changing or revoking its API can disable a VERA feature without notice.
7. AI safety
The approval workflow is the primary AI safety control: generated content is a draft until a person approves it, and the code path that performs an external action checks for that approval.
VERA sends prompts to third-party model providers over commercial APIs, sends only what the task requires, and does not permit training on those inputs. Image generation splits the work so the AI produces a background while VERA draws text and logos deterministically, which keeps brand copy accurate rather than hallucinated.
AI output can be wrong, and the AI Usage Policy states plainly which uses are prohibited, including relying on VERA for legal, medical, or financial advice, or for decisions about credit, employment, housing, or insurance.
8. Responsible disclosure
Report a vulnerability to support@myvera.io. We acknowledge within 3 business days and assess within 10. Good-faith research within the boundaries in the Security Policy is authorized, and we will not pursue legal action over it. VERA does not operate a paid bounty program.
9. Contact the team
Security: support@myvera.io. Privacy and data rights: support@myvera.io. Legal, DPA countersignature, and contracts: support@myvera.io. Support: support@myvera.io. Security questionnaires and vendor reviews: sales@myvera.io.
Change history
Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.
- v1.0July 28, 2026
Initial Trust Center published.
Questions about this document?
Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.
Related
This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.
