generated: '2026-08-05' method: searched source: https://vrify.com/legal/security docs: - https://vrify.com/legal/security - https://help.vrify.com/en/articles/11025335-data-security-at-vrify - https://vrify.com/articles/data-security-and-transparency-at-vrify trust_center: hosted: false note: >- VRIFY publishes no dedicated trust-center host (trust.vrify.com and security.vrify.com do not resolve; vrify.com/trust, /security and /compliance return 404). Its compliance posture is published as a legal page at /legal/security plus a customer-facing help-centre article. The SOC 2 report itself is not self-serve — it is released on request by email. page: https://vrify.com/legal/security page_last_modified: '2024-02-23' report_request: mailto:info@vrify.com certifications: - name: SOC 2 Type II status: certified scope: >- All five Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy — as of January 2026. authority: AICPA evidence: https://help.vrify.com/en/articles/11025335-data-security-at-vrify quote: >- "As of January 2026, this certification covers all five SOC 2 Type II Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy." report_available: on-request report_contact: info@vrify.com practices: - area: security program claim: >- "Our multi-layered security environment follows the principles of least privilege, separation of duties, defense in depth, and usability." source: https://vrify.com/legal/security - area: encryption at rest claim: >- Customer data is stored in AWS cloud databases and Amazon S3 buckets and "encrypted at rest using AES-256 encryption through AWS-native encryption mechanisms", covering databases, object storage and backups. source: https://help.vrify.com/en/articles/11025335-data-security-at-vrify - area: encryption in transit claim: >- Not stated on the security page. Observed at the edge: TLS 1.3 with HSTS max-age 31536000 on vrify.com, and HSTS with includeSubDomains + preload on services.vrify.com. source: security/vrify-domain-security.yml - area: access control claim: >- "Within the VRIFY cloud environment, access controls are tightly restricted to authorized personnel only. All VRIFY employees complete regular security training and device compliance checks." source: https://help.vrify.com/en/articles/11025335-data-security-at-vrify - area: model training data claim: >- Geospatial data used to train VRIFY Predict models is anonymized in four stages — data aggregation (company names and project specifications stripped), unique numeric asset identifiers replacing names, coordinate masking into a normalized index range, and conversion to a numerical image matrix that retains no coordinates or project information. source: https://help.vrify.com/en/articles/11025335-data-security-at-vrify - area: authoritative document claim: >- The help-centre security article explicitly disclaims contractual force; the Client Terms of Service is named as the authoritative data-storage agreement. source: https://vrify.com/legal/client-terms-of-service gaps: - No /.well-known/security.txt on vrify.com (404) — see well-known/vrify-well-known.yml. - No published vulnerability-disclosure policy, security contact, or bug-bounty program. - No subprocessor list published. - No self-serve trust portal; the SOC 2 report requires an email request. x-evidence: - url: https://vrify.com/legal/security http_status: 200 fetched: '2026-08-05' - url: https://help.vrify.com/en/articles/11025335-data-security-at-vrify.md http_status: 200 fetched: '2026-08-05' - url: https://vrify.com/security http_status: 404 fetched: '2026-08-05'