Trust Center // Security & Privacy

Security, by design.

A plain-English summary of the controls applied to client engagements and the data handled by this site.

Trust Center // Public
Controls
0
Encryption
TLS+E0E
Framework
GDPR
CTRL-01

Data in transit

All traffic is served exclusively over HTTPS (TLS). Document exchange happens over end-to-end encrypted channels established per engagement.

CTRL-02

Data at rest

Application data is stored in a managed Postgres database with row-level security enabled. Access is restricted by policy to the authenticated owner or a trusted backend role.

CTRL-03

Authentication & access

Sign-in uses industry-standard authentication. Administrative areas are gated by server-validated role checks — never client-side flags.

CTRL-04

Secret management

API keys, database credentials, and third-party tokens are stored as server-only secrets. They are never shipped to the browser.

CTRL-05

Confidentiality

Every client engagement is governed by a written NDA. Findings, source documents, and counterparty identifiers are shared only with named recipients.

CTRL-06

Privacy

We process personal data only to deliver requested services. See our Privacy Policy for the legal basis, retention, and data-subject rights aligned with GDPR principles.

CTRL-07

Logging & monitoring

Server-side logs capture operational events needed to detect abuse and debug failures. Logs exclude document contents and are accessible only to authorized engineering staff.

CTRL-08

Vulnerability handling

If you believe you have found a security issue, contact us via the secure intake form with a description and reproduction steps. We will acknowledge promptly and coordinate a fix.

This page describes Veritas Ledger Global's own controls. Statements here are not an independent certification or audit attestation. Specific compliance obligations for a given engagement are addressed in the engagement letter.