Security

Security is the product.

VERA works across your whole operation, so trust can't be an afterthought. Approve-first actions, encrypted credentials, least-privilege access, and a complete audit trail are built into how it runs.

Approve-first by design

VERA proposes every external action, posts, sends, spends, changes, and waits for your explicit approval before it acts. Nothing meaningful happens on your behalf without a click from you.

Encrypted credentials

Access tokens and connector secrets are encrypted at rest in a per-user secrets store. VERA reads only what it needs at the moment it needs it, and never exposes raw keys back to the interface.

Least-privilege access

When you connect a tool, you control exactly what VERA can read and do. Scopes are kept as narrow as the task allows, and you can disconnect any platform at any time.

Full audit trail

Every proposal, approval, and action is logged with what happened and when, so you always have a complete, reviewable history of everything VERA has done in your workspace.

Your data stays yours

We never sell your data or use it to train models for other customers. It exists to help VERA do your work, and disconnecting a tool stops that access immediately.

Demo-safe by default

Every connector ships with a working demo path, so you can evaluate the full workflow before wiring up a single real account or API key. Zero exposure while you kick the tires.

How we protect your workspace

Encryption in transit & at rest

All traffic is served over HTTPS, with plain HTTP upgraded and HSTS asserted in production. Connector credentials are encrypted with AES-256-GCM under a key held separately from the session-signing secret.

Scoped connector permissions

OAuth connections request the minimum scopes required for the features you use, and you can review or revoke access for any connected platform whenever you want.

Isolated per-user data

Each workspace's data and credentials are isolated. VERA operates within your account's boundary, it never mixes one customer's context into another's.

Human-in-the-loop actions

The approval gate is enforced in the product, not just a policy. High-impact actions are held for your sign-off, with a clear preview of exactly what will happen.

Frequently asked

Can VERA post, send, or spend without me?
No. VERA proposes each external action and holds it until you approve. Every real action is yours to confirm, with a full log afterward.
How are my connected accounts protected?
Access tokens are encrypted at rest in a per-user secrets store, scopes are kept minimal, and you can disconnect any platform at any time to revoke access.
Do you use my data to train models?
No. We never sell your data or use it to train models for other customers. It's used only to help VERA do the work you ask it to do.
How do I report a security concern?
Email support@myvera.io with the subject line "Security report". We aim to acknowledge within 3 business days and to assess within 10. Good-faith research inside the boundaries in our Security Policy is authorized.
Do you have SOC 2, ISO 27001, MFA, or SSO?
No, not yet, and we will not imply otherwise. The Security Policy lists every control that is in place and, in a section of equal length, every control that is not. Read that page before a vendor review.

Going deeper

This page is the overview. The Security Policy is the control-by-control record, including an explicit list of what we have not built yet, and the Trust Center answers the questions a vendor review asks.