Information we process
Account, workspace, membership, integration, operational, and evidence data needed to provide Veriom. This can include repository metadata, bounded source evidence, scanner observations, architecture relationships, review artifacts, and actions approved by your team.
How information is used
To authenticate users, ingest authorised evidence, produce architecture and security reviews, provide support, secure the service, measure reliability and cost, and meet legal obligations.
Confidential customer data
Customer evidence is workspace-scoped and treated as confidential service data. Access is limited by role and service purpose. Veriom does not publish customer source, findings, reports, or prompts as marketing content.
AI processing
Veriom sends bounded, redacted context to provider-pinned models through LLMGateway. Requests use store false and the gateway organisation is configured for metadata-only retention. Veriom persists final structured artifacts and measured usage, not hidden reasoning or model tool transcripts.
Product telemetry
Operational logs and optional analytics are separate. Logs use identifiers, status, latency, and failure metadata. Optional website analytics stay disabled until consent and must not contain repository source, findings, evidence, secrets, prompts, or report contents.
Retention and deletion
Retention depends on the data class, workspace policy, and service lifecycle. Workspace deletion enters an auditable workflow covering tenant data, objects, vectors, reports, and credentials. Backups and provider records may follow their documented expiry windows.
Security and access
Veriom uses tenant-scoped authorization, row-level database policies, encrypted transport, bounded workers, expiring credentials, and auditable administrative actions. No system can promise zero risk, so suspected exposure should be reported immediately.
Questions and requests
Contact hello@veriom.ai for privacy, confidentiality, access, correction, export, or deletion requests. We may need to verify identity and workspace authority before acting.