Trust & Safety

Security at Verifrs

Financial reporting data requires explicit ownership, isolation and accountability. Verifrs applies organisation scope, role-based decisions and attributable records across the reporting workflow.

Tenant-isolated data

Separation of duties

Evidence at every decision

Security control domains

Controls designed around financial-reporting risk.

Enterprise-grade security and compliance at Verifrs.

Validated core

1. In-Depth Defense

Our security strategy is based on the principle of defense in depth:

  • Encryption at rest is provided through managed database and storage infrastructure.
  • Data transmitted between the browser and platform services uses encrypted transport.
  • Secrets and service credentials are held outside the application source and managed through deployment controls.
Validated core

2. Infrastructure Security

Verifrs uses managed production infrastructure with separate deployment environments and provider-level operational controls.

  • Production data is logically separated by organisation and protected by server-side authorization checks.
  • Deployment and hosting providers supply network and availability protections for exposed services.
  • Dependencies, application changes and production errors are reviewed through the engineering control process.
Validated core

3. Application Security

We implement rigorous security practices in our development lifecycle:

  • Secure Coding: Our engineers follow OWASP guidelines to prevent common vulnerabilities.
  • Role-Based Access Control (RBAC): Granular permissions ensure users only access what they're authorized to see.
  • Audit Logs: Critical actions are logged for security transparency.
Validated core

4. Compliance & Certifications

We are committed to maintaining the highest compliance standards:

  • Privacy and data-handling obligations are scoped with each design-partner engagement.
  • Verifrs does not currently claim SOC 2 or ISO certification; independent assurance remains roadmap work.

Transparent product maturity

Security assurance without unsupported certification claims.

We distinguish implemented product controls from independent assurance and future certification work, and provide design partners with evidence for their own review.

01

Implemented controls

Tenant isolation, authorization checks, audit events and secure transport are part of the product architecture.

02

Independent assessment

External penetration testing and formal control assurance are tracked as production-assurance work, not implied as complete.

03

Responsible disclosure

Security concerns can be reported directly for triage, remediation and documented follow-up.

Last updated: July 18, 2026

5. Reporting a Vulnerability

If you believe you have found a security vulnerability in Verifrs, we encourage you to let us know right away. We will investigate all legitimate reports and do our best to quickly fix the problem.