TRUST CENTER

Current status. Not aspirational.

Certifications in progress, in place, and on the roadmap — with honest dates. Responsible disclosure scope and DPA template available on request.

01

Status

ItemStatusNote
SOC 2 Type IIn progressIndependent auditor engaged. Expected Q3 2026.
SOC 2 Type IIPlannedBegins 90 days after Type I report is issued.
ISO 27001EvaluatingScoping with customers who need the control mapping.
Pen testQuarterlyExternal firm, report available under NDA.
Responsible disclosurePublicScope, contact, and rewards below.
02

Responsible disclosure

Email info@verosek.com. PGP fingerprint is listed on the /trust page of docs.verosek.com.

In scope: the gateway, the Shield ML service, the admin console, and the official Python SDK. Out of scope: third-party connectors operating under their own policies.

We acknowledge within one business day, triage within five, and remediate or mitigate validated high-severity issues within thirty days.

03

Privacy and DPA

Self-hosted Verosek deployments never transmit your data to us. The managed PaaS (waitlist) carries a DPA template derived from EDPB and CNIL guidance. Request a copy from info@verosek.com.

Privacy policy and DPA template are available on request under NDA.