Trust & Data Protection
Enterprises trust VERYX with confidential information because the controls are real and verifiable — not promises. Tenant isolation, a tamper-evident audit trail, encryption, multi-factor authentication, UK data residency and full GDPR data control.
Every state change is written to an append-only, SHA-256 hash-chained ledger and event store. Tampering is mathematically detectable — you can verify the chain is intact at any time.
Strict tenant isolation: every record is scoped to its workspace and every query is constrained by tenant — verified live, with zero cross-tenant records. Defense in depth goes further with database row-level security available at the data store itself. A customer only ever sees another organisation’s data for a single project they have been explicitly invited to collaborate on, and nothing beyond it — never the other party’s other projects, wallet balance or subscription.
Documents and records carry a classification (public, internal, confidential, restricted). Confidential and restricted items require an explicit permission, and every access is audited.
Encryption in transit (HTTPS/HSTS), provider-managed encryption at rest, and AES-256-GCM field-level encryption for sensitive secrets; zero-trust RBAC on every request; multi-factor authentication; immediate session revocation; and account lockout after repeated failures. True client-side end-to-end encryption is not offered, by design: the governed OS and its AI must process your data server-side to operate.
UK data residency by default, a complete hash-chained audit trail, structured operational logging, and GDPR data control — export or request erasure of your data on demand.
AI is metered transparently at an immutable platform multiplier (×3 baseline, up to ×10 by requirement class) that cannot be altered at the customer layer. Every AI run is pre-authorized against your balance and budgets before it starts — hard caps and per-scope budgets mean spend is bounded, and a run that fails is never charged. No surprise pricing.
Every ACU purchase and spend also posts to a double-entry ledger whose debits and credits always balance, alongside the hash-chained ACU ledger — usage, spend and revenue reconcile to the penny and are auditable at any time.
CQRS over an append-only, hash-chained event store means every decision and AI action is reproducible by deterministic replay and exportable as an evidence pack — every decision can be replayed and proven.
Stated honestly: aligned today, with formal certifications underway. We never claim a certification we don't hold.
Data subject rights, UK residency, export and erasure operational today.
Information security management — controls implemented; certification in progress.
Trust-services criteria — controls mapped; formal audit planned.
AI management system — governance controls aligned; certification planned.
Inside every workspace, the Trust & Data Protection centre verifies the audit and event chains live, shows MFA coverage, confirms zero cross-tenant records, and lets you export or erase your data on demand. Security is something you can check, any time.