1. Scope and security documentation
This policy describes the public security expectations for Veriad’s website and services. Deployment-specific controls, incident terms, and service commitments are governed by your signed agreement. Discuss requirements with us before supplying information that needs a particular hosting location, access restriction, or regulatory arrangement.
Our security overview and Trust Center provide starting points for assessment. Contact us for documentation and the scope of controls relevant to your service.
2. Accounts and access
Limit workspace membership and connected-account permissions to people who need them. Use strong, unique credentials and enable additional authentication protections offered by your identity or account provider. Review access when people change roles or leave your organisation.
Keep access tokens, passwords, API keys, and private booking or demo credentials confidential. Avoid placing secrets in prompts or uploaded documents. Notify us promptly if you suspect unauthorised access, and revoke affected provider permissions where appropriate.
3. Campaign data and AI
Your creative assets, brand guidance, and campaign context remain your content. We process that material to deliver the services you request. Veriad does not use customer campaign content to train AI models.
Service delivery can involve storing uploaded assets, workspace records, and generated analyses. Provider arrangements and retention requirements should be reviewed for your deployment. Request deletion through your account contact; our Privacy Policy explains retention and the distinction between Veriad records and third-party accounts.
4. Connected services and operational safeguards
Check requested permissions before authorising an integration. Give access only to accounts you are entitled to connect, and review instructions before enabling workflows that affect published material or campaign settings. Disconnect integrations that are no longer needed.
Security depends on both Veriad and the providers supporting your workflow. Ask us about data flow, storage protection, access management, and available deployment options during your security review. Public policy text is not a promise that every enterprise control is included in every demonstration or subscription.
5. Assurance and certification status
Veriad’s ISO 27001 and SOC 2 Type II programmes are in progress. They should not be treated as completed certifications or audit reports. Consult the Trust Center or contact us for current status, evidence, and the scope of any assessment, including CASA Tier 2.
Customers with procurement questionnaires or contractual security requirements can contact rohan@veriad.com to arrange a review.
6. Report a vulnerability or incident
Email rohan@veriad.com with the subject “Security report”. Include the affected service or URL, when you observed the issue, a description of its impact, and the minimum steps needed to reproduce it. Provide a way for us to reach you.
Do not include passwords, live tokens, or other people’s personal information in an initial report. If sensitive evidence is necessary, ask us to arrange an appropriate way to share it. We will assess reports and coordinate investigation and remediation as appropriate; this policy does not promise a fixed response time or bounty payment.
7. Responsible testing
This policy is not permission to test systems without authorisation. Agree the scope with us first. Use your own test accounts, minimise data access, and stop if you encounter another person’s information.
Do not disrupt service, perform denial-of-service testing, use social engineering, install persistence, alter other customers’ data, or publicly disclose sensitive details before there has been a reasonable opportunity to investigate. Third-party systems require their owners’ permission.
8. Incident handling and updates
When a security concern affects customer information, we assess its scope, take appropriate containment and remediation steps, and communicate with affected customers and authorities as required by applicable law and contractual obligations. Keep your organisation’s security contact details up to date.
We may update this policy as our services and security practices develop. The revision date appears above. For questions, contact Veriad, Inc. at rohan@veriad.com.
Related policies