Security
Your company is sensitive information. We treat it that way.
Effective August 18, 2026
Company isolation
Venturs uses authenticated access and company/project scoping for workspaces. Authorization is checked on the server and supported by database controls where applicable.
Authentication and access
Account sessions are used to protect workspace access. Security-sensitive operations check the authenticated user, ownership, and requested resource rather than relying only on a client interface.
Private files and upload protections
Uploaded evidence is handled through the application’s authorization flow. The upload boundary validates approved file types, size, and filename length before accepting a file. We do not describe this as malware scanning.
Application protections
Current controls include secure transport policy, security headers, request validation, rate limiting on selected routes, safe URL validation, bounded metadata, and safe error responses. Service credentials are not intended for browser exposure.
Activity logging and minimization
Certain security-significant actions are recorded for operational and security purposes, including a request identifier, actor, action, and bounded metadata. Venturs aims to process only information needed to provide and protect the requested service.
Incident response and disclosure
Verified, Inc. maintains a documented incident-response process and security operating procedures. Report suspected vulnerabilities through responsible disclosure. Please do not access, alter, or retain another customer’s data while testing.
Compliance posture
Venturs does not currently claim that Verified, Inc. has completed a SOC 2 examination or obtained SOC 2 certification for Venturs. We are building the Venturs security program with future assurance and compliance requirements in mind.