Trust & security
Your data. Your company. Your control.
Your books, your customers, your documents. They are in VEDA Workspace to run your business — not to become someone else's product. This page describes the controls that hold, and the rules VEDA works under.
Your data
What we do, and do not do, with your data
Stated as commitments we can stand behind, and no further. Where the honest answer depends on a specific deployment, we say so and answer it in writing rather than publishing a promise we cannot prove.
We do not sell your workspace content
We do not sell what your organization puts into the workspace, and we do not make it available to third parties for their own independent purposes.
We do not train models on your business data
Verion does not use your workspace content to train models. Where a request is processed by a third-party model provider, that provider acts as our service provider under an agreement with us.
Ask, and we will put the provider position in writing
What a specific model provider does about training and retention depends on the configuration in force for a deployment. We do not publish a blanket promise on someone else's behalf. If your organization needs a written commitment for your workspace, ask us and we will confirm the position that applies to you.
Ending a subscription is not a deletion
A paid subscription cancellation, refund, or expiry changes access and billing — none of them deletes your workspace by itself. When you ask us to delete data we do so, and we tell you if something must be retained and why.
VEDA
The rules VEDA works under
VEDA is the assistance layer of the workspace. It is useful because it can reach your business context — which is exactly why its limits matter more than its abilities.
VEDA sees what you see — no more
A VEDA request runs under the permissions of the person who made it, inside the modules the organization has enabled. It has no separate, wider access of its own, so it cannot surface a record its user could not open themselves.
It prepares work; people decide
VEDA drafts and prepares. Where an action matters — posting, approving, sending — it goes to a person through the same approval path any other user would follow. It is assistance for a human to review, not an automated decision made on your behalf.
AI output can be wrong
We say this plainly rather than in a footnote: generated output can be inaccurate, and it is presented for review. Accounting figures remain the responsibility of the people who approve them.
Its work is traceable
What VEDA prepared, and what a person did with it, is recorded alongside the rest of the workspace's history — so an entry it helped draft has the same provenance as one typed by hand.
Workspace
How the workspace is protected
Controls that are implemented in the product today, described in the terms a business needs rather than in engineering vocabulary.
One organization, one boundary
Every workspace belongs to a single organization, and its records stay inside it. Company and organization scope is enforced on the server for each request, not chosen by the browser — a request for data outside your boundary does not return it.
Access follows roles, not links
What a person can see and do is decided by the role their organization gives them. Permissions are checked server-side on every operation, so a link, a saved URL, or a stale tab does not widen anyone's access.
Approvals are part of the record
Where a workflow requires approval, the approval is recorded with it: who approved, and when. Accounting work that has been reviewed cannot be quietly rewritten behind the reviewer's back.
An audit trail you can act on
Security-relevant actions and accounting events are written to server-side audit records, so an incident or a disputed figure can be investigated against evidence rather than recollection.
Encrypted in transit
Traffic between your browser and the service runs over HTTPS. Sign-in credentials are stored only in hashed form; we never store them in a form we could read back.
Payment details never reach us
Card payments are handled by Stripe. Your full card number and security code are transmitted to Stripe and are never received or stored by Verion — we hold only the card brand and last four digits needed to show you which card is on file.
Backups and recovery
Production data is backed up on a schedule and held off the production host, so a failure of the running system is not a loss of your books.
Changes go out under control
A production release takes a verified database backup before anything moves, deploys a specific pinned build rather than a floating tag, and is checked for health and basic function before it is accepted. The path back to the previous version is written down as part of the release, not improvised during an incident. Database migrations are versioned and applied in order.
On certifications
Verion does not currently hold a SOC 2, ISO 27001, or equivalent third-party attestation, and we do not claim one. What is described on this page is what the product does. If your procurement process needs a security questionnaire completed, or specific evidence about how your workspace is operated, write to hello@verion.one and we will answer it directly.
Found a vulnerability? Report it to the same address. Please give us a way to reach you and enough detail to reproduce it, and give us a reasonable window to fix it before disclosing it publicly.