Security, by design.
A plain-English summary of the controls applied to client engagements and the data handled by this site.
Data in transit
All traffic is served exclusively over HTTPS (TLS). Document exchange happens over end-to-end encrypted channels established per engagement.
Data at rest
Application data is stored in a managed Postgres database with row-level security enabled. Access is restricted by policy to the authenticated owner or a trusted backend role.
Authentication & access
Sign-in uses industry-standard authentication. Administrative areas are gated by server-validated role checks — never client-side flags.
Secret management
API keys, database credentials, and third-party tokens are stored as server-only secrets. They are never shipped to the browser.
Confidentiality
Every client engagement is governed by a written NDA. Findings, source documents, and counterparty identifiers are shared only with named recipients.
Privacy
We process personal data only to deliver requested services. See our Privacy Policy for the legal basis, retention, and data-subject rights aligned with GDPR principles.
Logging & monitoring
Server-side logs capture operational events needed to detect abuse and debug failures. Logs exclude document contents and are accessible only to authorized engineering staff.
Vulnerability handling
If you believe you have found a security issue, contact us via the secure intake form with a description and reproduction steps. We will acknowledge promptly and coordinate a fix.
This page describes Veritas Ledger Global's own controls. Statements here are not an independent certification or audit attestation. Specific compliance obligations for a given engagement are addressed in the engagement letter.
