Ir al contenido principal

Trust & Security

Security you cancheck, not just trust

Verian holds the schedule, contracts, and cost position of capital projects — the three things a project cannot afford to leak or lose. This page sets out exactly how that data is protected, where it lives, and what we have and have not yet earned.

Last updated September 2026

Architecture

This is the architecture

One cloud, one boundary, and a model we host ourselves. Drawn at the boundary level on purpose — the component-level architecture goes out with the security package, not on a public page.

Hosting

Microsoft Azure

one cloud, no resellers

Inference

Self-hosted model

our GPUs, our weights

Provisioning

Infrastructure as code

every resource in git

Your peoplebrowser · SSOyour directory stays the source of truthVerian MobileiOS · Androidtasks · photos · approvals, from sitethe device is never trusted —permissions are decided on the serverVERIAN-CONTROLLED INFRASTRUCTUREApplication tierisolated per tenantEncrypted data tierAES-256 at restPrivate language modelruns on our own GPUsfine-tuned open weights · no vendor API in the pathAudit trailappend-onlyEncrypted backupspoint-in-time recoveryHTTPS · TLSsame API,same rulesencryptedin-tenant inferenceencryptedCustomer data does not cross the dashed boundary.

Deliberately drawn at the boundary level. The component-level architecture — every service, datastore and control — is in the security package, which we send under NDA. Hosting region is pinned per deployment and written into your agreement.

FIG. 01WHAT SITS INSIDE THE BOUNDARY, AND WHAT NEVER CROSSES IT

Standard

Multi-tenant cloud

The default. Shared infrastructure, logically isolated tenants, managed and patched by us.

  • Tenant isolation enforced server-side on every query
  • Encrypted in transit and at rest
  • Rolling updates with no action from your team
  • Same controls for web and for Verian Mobile on iOS and Android

Enterprise

Single-tenant deployment

Your own isolated environment — dedicated database, dedicated compute, no shared data plane with any other customer.

  • Dedicated database and storage, not a shared cluster
  • Hosting region pinned at provisioning, written into your agreement
  • Change windows aligned to your release calendar

Isolation

One tenant cannot reach another

Not because the interface hides the option — because the server refuses the query. The check happens before any row is read, and it is the same check for the web app and for the field app.

INBOUND REQUESTAUTHORISATIONRESOLVED SERVER-SIDE · NEVER FROM THE CLIENTTENANT ATENANT BTENANT CCARRIES ITS OWNTENANT CREDENTIALPASSESASKS FOR ANOTHERTENANT'S RECORDREFUSEDNO ROW IS READ · THE ATTEMPT IS LOGGED
FIG. 02THE CHECK SITS IN FRONT OF THE DATA, NOT IN FRONT OF THE BUTTON

AI and your data

Your data does not train our models

Verian is AI-native, so this is the sharpest question in any review. Four commitments, and they hold for every model provider we run.

No third-party model ever sees your data

We run our own fine-tuned model on our own GPUs. Your contracts and schedules are never sent to an outside model provider — in production the platform refuses to make that call at all, and every attempt is logged.

Nothing is trained on your data

The model is not fine-tuned on customer content. Prompts are processed in memory for your request and are not retained as training data — there is no vendor in the path who could retain them either.

Traceable outputs

AI-generated findings cite the clause, activity, or line item they came from, so a human can check the work instead of trusting it.

Human decision rights

The platform drafts, flags, and forecasts. Approving a variation, issuing a notice, or committing cost stays a human decision with a named approver.

Controls

These controls are in force

Grouped the way a security review reads them, so you can answer a questionnaire straight off this page.

Exhibit A

Data protection

4 controls

Encryption in transit

All traffic to and from the platform is served over TLS. Plaintext HTTP is redirected, never accepted.

Encryption at rest

Databases, object storage, and backups are encrypted at rest with AES-256 by the underlying platform.

Backups and recovery

Managed automated backups with point-in-time recovery, so a bad import or a deletion is recoverable rather than terminal.

Deletion on exit

When a contract ends, your data is deleted on request — from the live system and from backups as they age out. We confirm in writing.

Exhibit B

Access control

5 controls

Role-based access

Permissions are granted by role at the project and organization level, so a subcontractor sees their scope and not your commercial position.

Single sign-on

SSO via your existing identity provider on enterprise plans, so joiners and leavers are governed by your directory, not by us.

Least privilege internally

Verian staff do not access customer project data as a matter of course. Access is scoped, justified, and time-bound.

Credential hygiene

Secrets live in managed secret storage, never in source control, and are rotated on personnel change.

The device is never trusted

Verian Mobile on iOS and Android sends requests, not decisions. Every permission is resolved on the server against your project roles — a device asking for something it should not see is refused, and the attempt is logged.

Exhibit C

Platform and infrastructure

4 controls

Managed, patched infrastructure

We build on managed cloud services so operating-system and database patching is continuous rather than a quarterly scramble.

Network protection

Edge protection and rate limiting sit in front of the application; the database is not exposed to the public internet.

Segregated environments

Development, staging, and production are separate. Production data is not copied into development.

Dependency monitoring

Automated alerts on known vulnerabilities in third-party packages, triaged on severity.

Exhibit D

Monitoring and audit

3 controls

Audit trail

Material actions — approvals, schedule changes, contract edits, cost movements — are recorded with actor, timestamp, and prior value.

Immutable history

Audit records are append-only. Correcting a mistake writes a new entry; it does not quietly rewrite the old one.

Application monitoring

Availability and error-rate monitoring with alerting to an on-call engineer.

Exhibit E

Organizational

3 controls

Background-checked staff

Employees and contractors with production access are vetted and bound by confidentiality obligations.

Security in review

Changes are peer-reviewed before merge. Security-relevant changes get an explicit second pair of eyes.

Vendor review

Subprocessors are reviewed before adoption and are bound by data-processing terms.

The record

A correction writes a new line

Every material action is recorded with its actor, its time, and what it replaced. Fixing a mistake appends; it does not quietly rewrite what was there. That is what makes the record usable in a dispute.

THE RECORDAPPEND-ONLY14 MAR 09:12SITE ENGINEERPROGRESS 62% — MECHANICAL14 MAR 11:40QSVALUATION ATTACHED15 MAR 08:05SITE ENGINEERPROGRESS 62% — MECHANICALSUPERSEDED15 MAR 16:22PLANNERFORECAST REBASELINED16 MAR 07:48SITE ENGINEERPROGRESS 54% — CORRECTEDNEW ENTRYSUPERSEDESTHE MISTAKE STAYS ON THE RECORD. THAT IS THE POINT.
FIG. 03AN ENTRY IS SUPERSEDED, NEVER OVERWRITTEN — BOTH SURVIVE

Compliance

What we hold, and what we do not

Plenty of vendors put certification logos on a page before an auditor has signed anything. We would rather you knew the real status and judged us on it.

GDPR / UK GDPR

We operate to GDPR obligations today: lawful basis, data-subject rights within 30 days, breach notification, and a DPA available on request.

In force today

SOC 2 Type II

Not yet held. We are building the control set toward an audit and will publish the report here when an auditor has issued one.

Planned — not yet held

ISO/IEC 27001

Not yet held. Our internal controls are designed against its objectives, which is not the same as being certified — and we won't imply otherwise.

Planned — not yet held

Penetration testing

Not yet completed by an independent third party. Scheduled ahead of general availability; the summary letter will be part of the security package.

Planned — not yet held

To be unambiguous: Verian does not currently hold SOC 2, ISO/IEC 27001, or any other security certification, and we do not display badges for certifications we have not earned. If a certification is a procurement gate for you, tell us — we will give you our target date in writing and the compensating controls in the meantime.

Subprocessors

Two companies touch your project data

One of them is our cloud provider. The other is standby GPU capacity we have not switched on yet. There is no third.

SubprocessorPurposeData processedStatus
Microsoft AzureHosting for the entire platform, including the GPU compute our own model runs onAll customer project data, at rest and in transitIn use
Elastic GPU hostAdditional capacity for our self-hosted model at peakPrompt content during inference only — never retainedNot yet in use

No model provider appears on this list. That is not an omission. The production model is ours and runs on our own infrastructure, so there is no third-party AI company to name — and nothing for one to retain, train on, or be breached with.

This page covers the platform. How this website handles a contact-form submission is set out in the privacy policy.

Report a vulnerability

If you believe you have found a security issue in Verian, email security@verian.io with enough detail to reproduce it. We acknowledge reports within two business days and will keep you updated until it is resolved.

We will not pursue legal action against researchers who report in good faith, stay within their own test data, and give us reasonable time to fix the issue before disclosing it.

If something goes wrong

We maintain an incident response process covering detection, containment, assessment, and notification. Affected customers are contacted directly with what happened, what data was involved, and what we are doing about it.

Where a breach is notifiable, we notify the relevant supervisory authority within the 72 hours GDPR requires, and we will not wait until the picture is complete to tell you that there is one.

Running a security review?

Ask for the security package: our architecture overview, control descriptions, DPA, and subprocessor list. If you have a vendor questionnaire, send it — we fill those in rather than pointing you back at this page.

Esta página de seguridad está disponible actualmente solo en inglés.