VERYXThe Enterprise Execution OS

Trust & Data Protection

Your data. Certain, secure, and yours alone.

Enterprises trust VERYX with confidential information because the controls are real and verifiable — not promises. Tenant isolation, a tamper-evident audit trail, encryption, multi-factor authentication, UK data residency and full GDPR data control.

Data certainty

Every state change is written to an append-only, SHA-256 hash-chained ledger and event store. Tampering is mathematically detectable — you can verify the chain is intact at any time.

No data leakage

Strict tenant isolation: every record is scoped to its workspace and every query is constrained by tenant. One customer can never read another customer’s data.

Confidential information security

Documents and records carry a classification (public, internal, confidential, restricted). Confidential and restricted items require an explicit permission, and every access is audited.

Data security

Encryption in transit (HTTPS/HSTS), provider-managed encryption at rest, and AES-256-GCM field-level encryption for sensitive secrets; zero-trust RBAC on every request; multi-factor authentication; immediate session revocation; and account lockout after repeated failures. True client-side end-to-end encryption is not offered, by design: the governed OS and its AI must process your data server-side to operate.

Business confidence

UK data residency by default, a complete hash-chained audit trail, structured operational logging, and GDPR data control — export or request erasure of your data on demand.

Governed AI economics

AI is metered transparently at an immutable platform multiplier (×3 baseline, up to ×10 by requirement class) that cannot be altered at the customer layer — no surprise pricing.

Court-grade governance

CQRS over an append-only, hash-chained event store means every decision and AI action is reproducible by deterministic replay and exportable as an evidence pack — every decision can be replayed and proven.

Certification roadmap

Stated honestly: aligned today, with formal certifications underway. We never claim a certification we don't hold.

UK GDPR / Data Processing

Data subject rights, UK residency, export and erasure operational today.

Aligned

ISO 27001

Information security management — controls implemented; certification in progress.

In progress

SOC 2 Type II

Trust-services criteria — control evidence collection underway.

In progress

ISO 42001

AI management system — governance controls aligned; certification planned.

Planned

Verifiable, not just stated

Inside every workspace, the Trust & Data Protection centre verifies the audit and event chains live, shows MFA coverage, confirms zero cross-tenant records, and lets you export or erase your data on demand. Security is something you can check, any time.