Annex II — Security Measures
This document describes the technical and organisational measures Veridue AI, Inc. implements to protect Customer Content and any personal data it processes on a customer’s behalf. Veridue may revise these measures at any time, provided that no revision materially reduces the protection they provide during a subscription term.
Hosting and residency
Customer Content is stored and hosted on servers located in the European Union. Veridue personnel and its sub-processors may access Customer Content from outside the European Union, subject to the measures in this Annex and to the Data Processing Agreement. Veridue’s hosting and infrastructure providers hold ISO 27001 certification, a current SOC 2 report, or an equivalent independent assessment, which Veridue verifies at least annually. The current providers and their locations are set out in Annex III.
Encryption
Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 or an algorithm of equivalent strength.
System access control
Access is granted on the principle of least privilege and by role. Multi-factor authentication is required for access to production systems. Access is reviewed quarterly and removed promptly when a person leaves or changes role.
Data access control and separation
Each customer’s data is logically separated from every other customer’s, and no customer can access another’s. Within a customer’s account, access between projects and invited parties is controlled by the permissions the customer configures. Development, testing and production environments are kept separate.
Personnel
All personnel with access to Customer Content are subject to written confidentiality obligations, background screening appropriate to their role, and security training on joining and periodically thereafter.
Sub-processors
Veridue engages sub-processors only under written terms imposing obligations equivalent to those in the Data Processing Agreement, and remains responsible for their performance. AI model providers are contractually required not to use Customer Content to train any model. The current list is at veridue.ai/legal/sub-processors.
Backup and continuity
Production data is backed up daily, and object storage is versioned and replicated. Backups are encrypted in transit and at rest, and point-in-time recovery is available. Veridue maintains a continuity plan, reviewed annually.
Logging and monitoring
Administrative and support access to Customer Content is logged and attributable to an individual. These logs are retained for at least 12 months. Systems are monitored for security events.
Vulnerability management
Systems are patched according to threat severity. Veridue commissions third-party penetration testing annually, and a summary is available to customers on request.
Incident response
Veridue will notify affected customers without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting their data, with the information they need to meet their own notification obligations.
Certifications
Veridue operates to SOC 2 Type II and ISO 27001 standards, with certification and the observation process ongoing. Its infrastructure providers are independently certified and Veridue’s own controls are continuously monitored and evidenced. Veridue expects to complete its SOC 2 Type II observation period by 31 December 2026, with ISO 27001 certification to follow, and completes customer security questionnaires on request.