PRIVATE PLATFORMOPERATOR · PRODIA SYSTEMS LIMITED
SYSTEM · VERIFIED
VERINEX
PlatformTechnologyVerificationResearchGovernanceUse CasesAbout
ACCESS CONSOLE↗REQUEST ACCESS

Legal CentreDocument

Security and Trust

Verinex is a governed discovery platform. Security is treated as a first-class design concern rather than a downstream control. This statement describes our current approach to security governance, access control, logging, vulnerability handling and continuity. It is descriptive rather than contractual, and it does not assert third-party certification.
Version2026-07-22-draft-1
Last updated22 July 2026
Canonicalhttps://verinex.dev/legal/security
Contents

Contents

  1. 01Security governance
  2. 02Identity and access
  3. 03Data protection
  4. 04Network and hosting
  5. 05Secure development lifecycle
  6. 06Logging and audit
  7. 07Vulnerability management
  8. 08Incident response
  9. 09Business continuity
  10. 10Personnel and confidentiality
  11. 11Third parties
  12. 12Customer responsibilities
  13. 13Reporting a suspected vulnerability
  14. 14Certifications and attestations

Contents

  1. 01Security governance
  2. 02Identity and access
  3. 03Data protection
  4. 04Network and hosting
  5. 05Secure development lifecycle
  6. 06Logging and audit
  7. 07Vulnerability management
  8. 08Incident response
  9. 09Business continuity
  10. 10Personnel and confidentiality
  11. 11Third parties
  12. 12Customer responsibilities
  13. 13Reporting a suspected vulnerability
  14. 14Certifications and attestations

Security governance

#

Security responsibility sits with the leadership of Prodia Systems Limited. Design decisions for Verinex are made with reference to established security principles including least privilege, defence in depth, separation of duties, secure defaults and auditability.

Identity and access

#

Access to the Verinex platform is credential-based and issued per user. Strong authentication is required, roles are configured on a least-privilege basis, and access is revoked when no longer required. Administrative access to production systems is limited to authorised personnel and is subject to logging.

Data protection

#

Data in transit is protected using industry-standard transport encryption. Data at rest is protected using encryption facilities provided by our hosting environment. Secrets are handled through dedicated secret-management facilities and are not stored in source repositories.

Network and hosting

#

Verinex is delivered from professionally operated hosting environments. Network exposure is limited to what is necessary for the service to function, with appropriate isolation between environments.

Pending verification

The specific hosting providers and regions used to deliver Verinex are pending confirmation and will be reflected in the Subprocessor Register.

Secure development lifecycle

#

Code changes are reviewed prior to deployment. Dependencies are monitored for known vulnerabilities. Changes are deployed through controlled pipelines with the ability to identify and roll back releases.

Logging and audit

#

Verinex generates operational and security logs and, as part of its governance model, verification and evidence records that describe how outputs are produced. These records support inspection, investigation and — for customers — internal audit.

Vulnerability management

#

Vulnerabilities are triaged and remediated on a risk basis. Suspected vulnerabilities may be reported under our Vulnerability Disclosure Policy.

Incident response

#

We maintain an incident response capability. In the event of a confirmed security incident affecting customer data, we will notify affected customers without undue delay in accordance with our contractual and legal obligations, including under the Data Processing Addendum.

Business continuity

#

Verinex is architected to support continuity of operations. Formal recovery-time and recovery-point objectives are set on a service basis and may be shared with customers under appropriate confidentiality.

Personnel and confidentiality

#

Personnel with access to production systems are subject to written confidentiality obligations and role-appropriate security controls.

Third parties

#

Third parties engaged to support delivery of Verinex are subject to appropriate contractual protections. Processors and subprocessors will be listed in the Subprocessor Register.

Customer responsibilities

#

Customers are responsible for the security of their own systems, endpoints, users and Customer Inputs, for configuring roles appropriately, and for reporting suspected compromise of credentials promptly.

Reporting a suspected vulnerability

#

If you believe you have identified a security vulnerability affecting Verinex, please follow the Vulnerability Disclosure Policy.

Operator

Prodia Systems Limited

Public brand: Verinex — https://verinex.dev

Registered office

Pending verification

Company number

Pending verification

VAT number

Pending verification

Security contact

Pending verification

Operator details pending

One or more operator details required by this document have not yet been verified for publication and are marked Pending verification. See LEGAL_INFORMATION_REQUIRED.md in the project repository for the outstanding items.

Certifications and attestations

#

Pending verification

Prodia Systems Limited does not currently claim ISO, SOC, third-party penetration-test or equivalent external attestation for Verinex. Any such attestations, if and when obtained, will be added by amendment to this statement.

This document is version 2026-07-22-draft-1. See Legal change log for the complete version history, and Legal Centre for all related documents.

VERINEX

Verinex is the flagship governed discovery platform developed by Prodia Systems Limited. Autonomous advancement — inspectable, defensible, reproducible.

Verified Autonomous Discovery

Platform

  • Platform
  • Technology
  • Verification
  • Research & Evidence
  • Governance
  • Use Cases

Access

  • Request Access
  • Console
  • Contact

Trust

  • Security
  • Responsible AI
  • Responsible Disclosure
  • Legal Centre

Company

  • About Verinex
  • Prodia Systems Limited ↗

Legal

  • Platform Terms
  • Privacy
  • Acceptable Use
  • Cookies
  • Intellectual Property
  • Deployment

© 2026 Verinex. Developed by Prodia Systems Limited. All rights reserved.

BUILD c3c2532 · 2026-07-22VERINEX.DEV