Security & trust

Operational data is somebody's contract. We treat it that way.

Verolane holds commitments, evidence and crew positions for regulated operations. This page is the summary; the trust pack behind it contains the reports, the register and the agreements.

ISO 27001Certified, annual surveillance
SOC 2 IIReport available under NDA
15 minRecovery point objective
30 daysSub-processor change notice
01 / 03

Controls

Eight controls, stated plainly.

Tenancy isolation

Every customer runs in a logically isolated tenant with row-level enforcement at the data layer, not in application code.

Data residency

Select UK, EU or US residency at tenant creation. Backups and search indexes stay in the selected region.

Encryption

TLS 1.3 in transit, AES-256 at rest, with customer-managed keys available on Estate agreements.

Access control

SAML single sign-on, SCIM provisioning, and roles scoped to region, contract and commitment tier.

Audit

Append-only log of every state change, rule firing and settlement decision, exportable to your SIEM.

Resilience

Multi-zone deployment, 15-minute recovery point objective, quarterly restore exercises with published results.

Vulnerability management

Continuous dependency scanning, annual third-party penetration test, and a coordinated disclosure programme.

Sub-processors

A published sub-processor register with 30 days' notice of any addition.

02 / 03

Assurance

What has been independently checked.

ISO 27001Certified, annual surveillance audit
SOC 2 Type IIReport available under NDA
UK GDPRDPA and SCCs on request
Cyber Essentials PlusRenewed annually

Position data has a boundary.

Crew location is used to predict drift on open commitments and is retained for thirty days. It is not exposed as an individual productivity report, and it is not available to any role outside the exception desk. That limit is a product decision, and it is written into the data processing agreement.

Disclosure without lawyers first.

We run a coordinated disclosure programme with a published contact, a 72-hour acknowledgement target and no legal threat as a first response. Confirmed findings are credited unless the reporter asks otherwise.

Report a vulnerability
03 / 03

Sub-processors

Who else touches the data.

The full register, with locations and purposes, is in the trust pack. Any addition is notified thirty days before it takes effect.

Summary of sub-processor categories
PurposeRegionDataNotice
Cloud infrastructure and storageUK / EU / USAll tenant data30 days
Transactional email and SMSEUContact name, address, message30 days
Error and performance monitoringEUPseudonymised technical events30 days
Support deskUKCorrespondence and account metadata30 days

Next step

Ask the hard questions early.

Security reviews get easier when they happen before the commercial conversation, not after it. Send your questionnaire and we will answer it in full.

  • Answered in your own format
  • Named security contact
  • Two working days