Security & trust
A clear security posture.
What is implemented today, what depends on a customer agreement, and what remains planned. Stated without unsupported certifications.
How to read this page
Implemented
Controls in place today
Contractual
Terms available by agreement
Planned
Not yet completed
Verifex handles regulated screening data. This page states our controls plainly and separates what is implemented today from what is a contractual commitment and what is planned. Security questions can be sent to hello@verifex.dev.
Implemented
Controls that are in place today:
- HTTPS required for all web and API traffic (TLS 1.2/1.3), with tested protocol configuration
- HSTS enabled with a one-year max-age
- Passwords hashed with bcrypt (12 rounds)
- API keys shown once and stored only as a one-way SHA-256 verifier, never in plaintext
- HMAC-SHA256 signatures on webhook payloads
- SSRF and path-traversal protection on outbound and file operations
- Content-Security-Policy, X-Frame-Options: DENY, and X-Content-Type-Options: nosniff headers
- Zod input validation on API endpoints
- CSV-injection prevention on data exports
- Per-key and per-IP rate limiting
- Fail-safe screening semantics: an unavailable, stale, or partial source is surfaced as such and never returned as a clear result
- Append-oriented audit logging — screening events recorded with source-list and algorithm versions
- Source-governance controls on ingested screening data
- CI secret scanning and dependency checks
- Automated regression and security tests
- Optional error tracking (Sentry) and operational alerting
- Application-level privileged admin controls: scoped permissions, expiring ALLOW/DENY grants, step-up, maker-checker, audit events and durable mutation receipts
- A documented incident-response process
- A responsible-disclosure channel
- Encrypted database backups to an off-site storage boundary, with restoration tested (last full restore drill: September 4, 2026)
Contractual
Commitments made through agreements with customers:
- A Data Processing Agreement (DPA) available for contractual review
- A commitment to put EU Standard Contractual Clauses (SCCs) in place for international transfers where required (under legal review; not all executed yet)
- 30 days' notice of new subprocessors where contractually required
See our current providers at /subprocessors.
Planned
Improvements we are working toward but have not completed:
- Two-factor authentication for dashboard users
- Formal infrastructure access management and corresponding public documentation beyond the application control plane
- Full-disk encryption at rest
- An independent penetration test
- A SOC 2 examination
Certifications & assurances
We describe our posture honestly. As of the last-updated date above:
- Verifex is not ISO 27001 certified.
- Verifex has not completed a SOC 2 examination.
- Verifex makes no formal GDPR certification claim.
- Verifex has not completed an independent penetration test.
Inherited hosting certification. Verifex infrastructure is hosted on Hetzner infrastructure covered by Hetzner Online GmbH's ISO/IEC 27001:2022-certified ISMS (Certificate ZN-2025-35, valid 27 Sep 2025 – 26 Sep 2028; scope: all hosting services and the data centers of Hetzner Online GmbH, including Nuremberg, Falkenstein/Vogtland and Helsinki). This certification covers the underlying hosting services and data-centre operations and does not constitute ISO 27001 certification of Verifex. Hetzner certification
Availability and status
Verifex makes no public uptime target or SLA. A service-level commitment is available only when it is expressly agreed with a customer. Live status is available at status.verifex.dev .
Responsible disclosure
Found a vulnerability? Please report it under our responsible-disclosure policy or email hello@verifex.dev.