Analytics your security review can sign off on.
Veritly reads from the warehouse you already run, models what it finds, and enforces permissions before results are returned. Every scheduled run leaves a trail — so the answer in front of your client is one you can defend.
What a reviewer actually asks.
Security reviews ask about three things, in this order. Here is where we land on each.
- The platform
Your warehouse stays the source of truth
- Veritly reads from the warehouse you already run. The one thing we persist is a source model — a table we build so queries resolve against a known shape — and we document what it holds. Credentials are encrypted at rest, connections are encrypted in transit, and every account is provisioned on least privilege.
- The people
Access is a role, not a habit
- Production access is limited to the people whose work requires it, granted from a defined role on joining and revoked on the last day. Everyone handling customer data is trained on how to handle it, and that training is refreshed rather than filed.
- The paperwork
We'll tell you where we actually are
- Veritly Ltd is registered in England and Wales and processes personal data under the UK GDPR and the Data Protection Act 2018. The formal attestations enterprise buyers ask for are in progress, and the table below says exactly which.
Veritly connects to the warehouse and the identity provider you already run.
PLACEHOLDER — swap for real vendor wordmarks once we've checked each brand's usage terms.
Where we stand on compliance.
We'd rather tell you where we are than put a logo on a page. This table is the current state of every standard customers ask us about.
| Standard | Status | Where we are today |
|---|---|---|
| UK GDPR / DPA 2018 | Aligned | Data controller registered in England and Wales. Lawful bases, retention periods, and subject-access handling are documented in our privacy policy. |
| EU GDPR | Aligned | Standard contractual clauses for transfers, and a data processing agreement available on request for customers processing EU personal data. |
| SOC 2 Type II | In progress | Controls are being implemented ahead of an observation window. We'll share the report with customers under NDA once it is issued. |
| ISO 27001 | Planned | On the roadmap behind SOC 2. Ask us where it sits if it's a hard requirement for your procurement process. |
Available on request
- Data processing agreement (DPA)
- Subprocessor list
- Completed security questionnaire (CAIQ or your own)
- Penetration test status letter
- Architecture and data-flow overview
- Incident response and breach notification policy
PLACEHOLDER — the attestation badge goes here, and only once the report has actually been issued. Leave it empty until then.
The controls a data lead expects.
Governance isn't a settings page bolted on at the end. It's the same semantic model every dashboard, document, and automation reads from.
Governed data model
- Access controlled at the view (table) and field (column) level
- Row-level filtering driven by user attributes
- Metric definitions versioned, reviewed, and merged like code
- Changes tested on a branch before they reach a live report
Security administration
- Granular permission roles
- Permissions at the user and the group level
- Attribute-based access control for flexible data permissions
- SAML single sign-on
Connectivity & processing
- Warehouse connections encrypted in transit (TLS 1.2+)
- Tunnelled connections for warehouses on private networks
- Credentials encrypted at rest with managed, rotated keys
- Your data is never used to train a model
One path, and it ends at your warehouse.
A question becomes a permission-filtered query against the warehouse you already run, and only the result comes back. The source model we build sits alongside your warehouse, not instead of it.
Your browser (on your device)
Authenticated session, SAML SSO available
Identity (runs on Veritly)
User and group membership resolved
Semantic layer (runs on Veritly)
Row and column rules compiled into the query
Your warehouse (runs on your infrastructure)
The query runs here. Only the result comes back
"Customer quote goes here — one or two sentences on what a Veritly security review changed for their team."
Our security practices, in detail.
The questions that come up in every security questionnaire, answered before you have to send one.
Not covered here? Ask us directly
Data & infrastructure
Infrastructure provider
Veritly runs on established cloud infrastructure providers with their own physical-security and availability programmes. We inherit their data-centre controls and layer our own access, network, and monitoring policy on top. Environments are separated so development work cannot reach production data.
Data encryption
Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256. Warehouse credentials and API tokens live in a managed secrets store under keys we rotate — never in application code or configuration files.
Access control
Access to production systems is role-based and granted on least privilege. Administrative access requires multi-factor authentication, is reviewed periodically, and is revoked as part of offboarding rather than as an afterthought.
Network security & system monitoring
Production networks are segmented and firewalled, with inbound access limited to the services that need to be reachable. Application and infrastructure logs are centralised and retained so an incident can be reconstructed rather than guessed at.
Data residency & retention
Veritly reads from the warehouse you already run, so your analytical data stays where your existing security review put it. We hold query metadata, definitions, and account records — retained per our privacy policy and deleted on request.
People
Formal security policy
We maintain written security, acceptable-use, and incident-response policies. Every employee and contractor acknowledges them, and they are reviewed at least annually rather than written once and left to age.
Onboarding & offboarding
Access is provisioned from a defined role on joining and revoked on the last day, covering cloud accounts, source control, and internal tooling. Background checks are carried out where the role and local law allow.
Security training
Everyone with access to customer data completes security awareness training, including phishing and secure-handling practice, with refreshers on a recurring schedule.
Development & vendors
Secure development & change management
All changes go through peer review and automated checks before merge. Deployments are versioned and reversible — the branch-and-review discipline we give you for metric definitions is the one we run our own codebase on.
Application monitoring
Errors and anomalies are surfaced to an on-call rotation with defined severities. Customer-affecting incidents are communicated to affected customers along with what happened and what changed as a result.
Penetration testing & vulnerability management
Dependencies are scanned continuously and patched on a severity-driven schedule. Third-party penetration testing is part of our path to SOC 2; ask us for the current status if it matters to your review.
Third-party vendor security
Subprocessors are reviewed before onboarding and reassessed periodically. A current list is available on request, and material changes are communicated to customers.
Reporting an issue, or reviewing us?
Write to hello@veritly.co.uk and a person will read it. We'll acknowledge a vulnerability report within two working days and keep you updated until it's closed.
Please give us a chance to fix an issue before disclosing it publicly. We don't run a paid bounty yet, but we will credit you in the fix notes if you'd like us to.
Bring it to your security review.
Veritly is in private beta. Join the waitlist and we'll come to you with the documentation your review needs.