Every customer runs in a logically isolated tenant with row-level enforcement at the data layer, not in application code.
Security & trust
Operational data is somebody's contract. We treat it that way.
Verolane holds commitments, evidence and crew positions for regulated operations. This page is the summary; the trust pack behind it contains the reports, the register and the agreements.
Controls
Eight controls, stated plainly.
Select UK, EU or US residency at tenant creation. Backups and search indexes stay in the selected region.
TLS 1.3 in transit, AES-256 at rest, with customer-managed keys available on Estate agreements.
SAML single sign-on, SCIM provisioning, and roles scoped to region, contract and commitment tier.
Append-only log of every state change, rule firing and settlement decision, exportable to your SIEM.
Multi-zone deployment, 15-minute recovery point objective, quarterly restore exercises with published results.
Continuous dependency scanning, annual third-party penetration test, and a coordinated disclosure programme.
A published sub-processor register with 30 days' notice of any addition.
Assurance
What has been independently checked.
Position data has a boundary.
Crew location is used to predict drift on open commitments and is retained for thirty days. It is not exposed as an individual productivity report, and it is not available to any role outside the exception desk. That limit is a product decision, and it is written into the data processing agreement.
Disclosure without lawyers first.
We run a coordinated disclosure programme with a published contact, a 72-hour acknowledgement target and no legal threat as a first response. Confirmed findings are credited unless the reporter asks otherwise.
Report a vulnerabilitySub-processors
Who else touches the data.
The full register, with locations and purposes, is in the trust pack. Any addition is notified thirty days before it takes effect.
| Purpose | Region | Data | Notice |
|---|---|---|---|
| Cloud infrastructure and storage | UK / EU / US | All tenant data | 30 days |
| Transactional email and SMS | EU | Contact name, address, message | 30 days |
| Error and performance monitoring | EU | Pseudonymised technical events | 30 days |
| Support desk | UK | Correspondence and account metadata | 30 days |
Next step
Ask the hard questions early.
Security reviews get easier when they happen before the commercial conversation, not after it. Send your questionnaire and we will answer it in full.
- Answered in your own format
- Named security contact
- Two working days