1. Overview

At Verity Audit, security is a top priority. We implement multiple layers of protection to ensure your audit data remains safe and confidential. This page describes the security measures we have in place.

Verified Security Measures

Independently tested and verified on our production environment

SSL/TLS Encrypted Bcrypt Hashing CSRF Protected Daily Backups Rate Limited SQL Injection Protected HSTS Enabled Secure Cookies Security Headers

2. Authentication & Access Control

2.1 Password Security

2.2 Session Management

2.3 Brute Force Protection

2.4 Role-Based Access Control

We implement 5 distinct user roles with granular permissions:

3. Application Security

3.1 Protection Against Common Attacks

3.2 Security Headers

We implement comprehensive HTTP security headers:

4. Data Security

4.1 Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS). We enforce HTTPS-only connections.

4.2 Multi-Tenant Data Isolation

Each organization's data is logically separated using organization-level access controls. Users can only access data belonging to their own organization. Every database query is filtered by organization ID.

4.3 Data Ownership

You retain full ownership of all data you upload to Verity Audit. We do not sell, share, or use your audit data for any purpose other than providing the service to you.

5. Infrastructure

5.1 Hosting

5.2 Backups

5.3 Monitoring

6. Compliance

Verity Audit is designed to support internal audit functions in accordance with the Global Internal Audit Standards (GIAS). Our workflow covers the complete audit lifecycle from planning through follow-up.

A Note on Certifications

We do not currently hold SOC 2 or ISO 27001 certifications. These certifications require significant investment and are typically pursued when customer demand justifies the cost. We are committed to implementing security best practices and will pursue formal certifications as we grow.

7. Responsible Disclosure

We take security seriously. If you discover a security vulnerability, please report it responsibly:

8. Questions

If you have security questions or need additional information for your procurement process, please contact us at [email protected].