Security + trust summary

One page your internal reviewer can forward.

Send this concise, dated summary to your IT consultant, compliance lead or principal. It mirrors the published trust suite without claiming certifications or controls Vericode does not hold.

Download PDF
What Vericode is

Authorised-contact verification with evidence.

Vericode is a browser-based authorised-contact verification service for Australian businesses. Staff send a one-time code to a mobile number already on file and retain evidence of the check's outcome.

Data residency

Customer and verification data — recipient details, messages and verification records — is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States.

Full residency detail

Evidence, not client files

Vericode stores the data needed to dispatch and evidence a verification: recipient details, message and provider metadata, timestamps, actors, outcomes and audit events. The product is not a document repository and does not require customers to upload client matter files to complete a verification.

Controls in practice

Six controls, with limitations stated.

Encryption in transit

Public services use HTTPS; production PostgreSQL enforces TLS 1.2 as its minimum protocol.

Encryption at rest

Primary records use Azure-managed PostgreSQL and managed disks with Azure platform encryption at rest.

Identity and access

Staff sign in through WorkOS. Access is workspace-scoped and sensitive exports require compliance-level permission.

Change checks

Pull requests run automated checks including secret scanning and end-to-end workflows. Mandatory branch protection and formal dependency scanning are planned.

Audit integrity

Authorised-contact events are ordered and hash-chained with event time, actor, outcome context and integrity hashes.

Backup and recovery

Azure PostgreSQL keeps seven days of backups. Geo-redundant backup is not enabled and formal RPO/RTO targets are not published.

Assurance and privacy

Certification status

Vericode does not currently hold an independent information-security certification. Formal certification work is planned. Provider certifications belong to the provider and are not Vericode certifications.

Privacy Act + GDPR posture

Vericode is an Australian business. Its handling of personal information is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.

Vericode is built for Australian businesses and does not publish a general claim of GDPR compliance. If an engagement involves people in the EEA or UK, contact [email protected] for a scoped assessment.

Subprocessor summary

Purpose and relevant location.

Microsoft AzureCore application and PostgreSQL · Australia East
MobileMessagePrimary SMS delivery · Australia
ClickSendSecondary SMS · Australia-based service; carrier delivery may vary
StripeBilling · global; processing may occur outside Australia
LoopsTransactional and lifecycle email · United States
WorkOSStaff identity and sign-in events · United States
CloudflareWebsite, DNS and delivery · global edge network
Service, sender and contacts

Published service posture

Check status.vericode.com.au. Product support targets a response within one Australian business day, with same-day attention for S1 and S2 during AEST/AEDT business hours. This is a support target, not a broader contractual SLA.

Verification messages are sent through Australian carriers MobileMessage or ClickSend, using Vericode's ACMA-registered sender ID, VERICODE.