Security & Data at Vereon AI
Automation and website systems can touch important business data, so access, storage, integrations and human oversight are designed deliberately rather than added at the end.
Access controls
- Private account areas require an authenticated session.
- Administrative access is checked server-side and cannot be enabled by a normal customer from the browser.
- Database row-level policies scope supported customer records to the appropriate authenticated user.
- Service-role credentials and other privileged secrets are used only on the server.
Integrations and webhooks
- Inbound provider events are validated using the verification mechanisms available for the relevant integration.
- Duplicate-event protection is used where repeated webhook delivery could otherwise create repeated actions.
- Production access is requested only when needed for an approved implementation.
- Customers should never paste passwords, private keys or secret API keys into ordinary forms or proposal notes.
Files and project data
Private storage is used where project assets should not be publicly accessible. Temporary signed links may be used when an authorised person needs short-lived access to a stored file.
AI safeguards
AI output can be imperfect. Vereon uses business rules, thresholds, exception handling and human review where the risk or judgement requires it. High-impact or sensitive decisions should not be delegated solely to an AI model without an appropriate review process.
Operational security
Vereon tests protected routes, access boundaries, production errors and key customer journeys as part of release checks. Security requirements can vary materially by client, industry, data type and integration, so project-specific controls are confirmed during implementation.
Report a concern
If you believe you have found a security or privacy issue, please use the contact page and avoid including unnecessary secrets or personal data in the initial message.