Encryption in transit
Public services use HTTPS. The production PostgreSQL service enforces TLS 1.2 as its minimum protocol.
Vericode is building its assurance programme in public. The controls below are those we can evidence today; planned work is labelled as planned.
Current assurance status
Vericode does not currently hold an independent information-security certification. Formal certification work is planned; provider certifications belong to the provider and are not Vericode certifications.
Public services use HTTPS. The production PostgreSQL service enforces TLS 1.2 as its minimum protocol.
Primary records use Azure-managed PostgreSQL and managed disks, with encryption at rest provided by the Azure platform.
Staff sign in through WorkOS. Application access is workspace-scoped and sensitive audit exports require compliance-level permission.
Pull requests run automated checks, including secret scanning and end-to-end workflows. Mandatory branch protection and a formal dependency-scanning programme are planned.
Authorised-contact events are ordered and hash-chained. Exports include event time, actor, outcome context and integrity hashes.
Azure PostgreSQL keeps seven days of backups. Geo-redundant backup is not enabled and Vericode does not yet publish formal RPO/RTO targets.
Microsoft publishes assurance material for Azure in its Trust Center. Those attestations cover Microsoft's platform controls, not Vericode's organisation or application controls.
Vericode stores the data needed to dispatch and evidence a verification: recipient details, message and provider metadata, timestamps, actors, outcomes and audit events. The product is not a document repository and does not require customers to upload client matter files to complete a verification.
Customer and verification data — recipient details, messages and verification records — is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States.
Read the data-residency detailWe triage reported security events, contain impact, preserve evidence and assess whether the Notifiable Data Breaches scheme applies. We notify affected parties and the OAIC when legally required. No shorter contractual notification SLA is published today.
Send a clear description, affected URL or component, reproduction steps and impact to [email protected]. Please do not access other people's data, disrupt the service or publish a finding before we have had a reasonable opportunity to respond.
Read the full disclosure policySecurity questionnaires, architecture context and current subprocessor information can be shared for an active review. Some documents remain subject to legal review.