Security and trust

Concrete controls. Honest status.

Vericode is building its assurance programme in public. The controls below are those we can evidence today; planned work is labelled as planned.

Current assurance status

Vericode does not currently hold an independent information-security certification. Formal certification work is planned; provider certifications belong to the provider and are not Vericode certifications.

Controls in practice

What protects the service today

Encryption in transit

Public services use HTTPS. The production PostgreSQL service enforces TLS 1.2 as its minimum protocol.

Encryption at rest

Primary records use Azure-managed PostgreSQL and managed disks, with encryption at rest provided by the Azure platform.

Identity and access

Staff sign in through WorkOS. Application access is workspace-scoped and sensitive audit exports require compliance-level permission.

Change checks

Pull requests run automated checks, including secret scanning and end-to-end workflows. Mandatory branch protection and a formal dependency-scanning programme are planned.

Audit integrity

Authorised-contact events are ordered and hash-chained. Exports include event time, actor, outcome context and integrity hashes.

Backup and recovery

Azure PostgreSQL keeps seven days of backups. Geo-redundant backup is not enabled and Vericode does not yet publish formal RPO/RTO targets.

Microsoft publishes assurance material for Azure in its Trust Center. Those attestations cover Microsoft's platform controls, not Vericode's organisation or application controls.

Data handling

Verification evidence, not client files.

Vericode stores the data needed to dispatch and evidence a verification: recipient details, message and provider metadata, timestamps, actors, outcomes and audit events. The product is not a document repository and does not require customers to upload client matter files to complete a verification.

Residency, with the exception stated

Customer and verification data — recipient details, messages and verification records — is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States.

Read the data-residency detail
Incident response

Report concerns directly.

We triage reported security events, contain impact, preserve evidence and assess whether the Notifiable Data Breaches scheme applies. We notify affected parties and the OAIC when legally required. No shorter contractual notification SLA is published today.

Vulnerability disclosure

Send a clear description, affected URL or component, reproduction steps and impact to [email protected]. Please do not access other people's data, disrupt the service or publish a finding before we have had a reasonable opportunity to respond.

Read the full disclosure policy
Due diligence

Additional documentation is available on request.

Security questionnaires, architecture context and current subprocessor information can be shared for an active review. Some documents remain subject to legal review.