Legal CentreDocument
Security and Trust
Security governance
#Security responsibility sits with the leadership of Prodia Systems Limited. Design decisions for Verinex are made with reference to established security principles including least privilege, defence in depth, separation of duties, secure defaults and auditability.
Identity and access
#Access to the Verinex platform is credential-based and issued per user. Strong authentication is required, roles are configured on a least-privilege basis, and access is revoked when no longer required. Administrative access to production systems is limited to authorised personnel and is subject to logging.
Data protection
#Data in transit is protected using industry-standard transport encryption. Data at rest is protected using encryption facilities provided by our hosting environment. Secrets are handled through dedicated secret-management facilities and are not stored in source repositories.
Network and hosting
#Verinex is delivered from professionally operated hosting environments. Network exposure is limited to what is necessary for the service to function, with appropriate isolation between environments.
Secure development lifecycle
#Code changes are reviewed prior to deployment. Dependencies are monitored for known vulnerabilities. Changes are deployed through controlled pipelines with the ability to identify and roll back releases.
Logging and audit
#Verinex generates operational and security logs and, as part of its governance model, verification and evidence records that describe how outputs are produced. These records support inspection, investigation and — for customers — internal audit.
Vulnerability management
#Vulnerabilities are triaged and remediated on a risk basis. Suspected vulnerabilities may be reported under our Vulnerability Disclosure Policy.
Incident response
#We maintain an incident response capability. In the event of a confirmed security incident affecting customer data, we will notify affected customers without undue delay in accordance with our contractual and legal obligations, including under the Data Processing Addendum.
Business continuity
#Verinex is architected to support continuity of operations. Formal recovery-time and recovery-point objectives are set on a service basis and may be shared with customers under appropriate confidentiality.
Personnel and confidentiality
#Personnel with access to production systems are subject to written confidentiality obligations and role-appropriate security controls.
Third parties
#Third parties engaged to support delivery of Verinex are subject to appropriate contractual protections. Processors and subprocessors will be listed in the Subprocessor Register.
Customer responsibilities
#Customers are responsible for the security of their own systems, endpoints, users and Customer Inputs, for configuring roles appropriately, and for reporting suspected compromise of credentials promptly.
Reporting a suspected vulnerability
#If you believe you have identified a security vulnerability affecting Verinex, please follow the Vulnerability Disclosure Policy.
Operator
Prodia Systems Limited
Public brand: Verinex — https://verinex.dev
Registered office
Pending verification
Company number
Pending verification
VAT number
Pending verification
Security contact
Pending verification