Skip to content

Trust & data handling

Last updated: 18 July 2026

You're about to tell a security product about your security. Fair enough to want a straight answer on what we hold, what we deliberately don't, and why we built it this way.

The rule we build to: hold less

Veritas Cyber is a self-assessment and document-generation tool. You answer plain-English questions about your own controls. We score them against published frameworks and generate your documents. Because that's all it does, we don't need the sensitive material a security vendor might otherwise hold, and we don't build features that would need it.

What we never collect

  • No credentials or secrets. We never ask for passwords, API keys, or access to any of your systems.
  • No scanning or agents. We install nothing on your devices, and we never connect to, probe or monitor your network. Nothing of ours runs in your environment, so there's no telemetry coming out of it.
  • No customer data of yours. Your answers describe your practices (“we back up daily”). They never include your customers' records.

What we do hold

  • Free assessment: your answers stay in your browser. If you ask us to email your snapshot, we store your email address and the level summary, not your individual answers.
  • With an account: your email, business details (name, industry, staff count), and your saved self-reported answers and results. That's the minimum we need to generate and refresh your documents.
  • Payments: handled by Stripe. We never see or store your card details.

The full detail, including how long we keep data and your rights, is in our Privacy Policy.

Where it lives

Account data sits in Supabase (Postgres) with row-level security, so only your signed-in account can read it. Documents are generated on demand from your answers and downloaded to you. We keep a log of what was generated, not a library of your PDFs. Email goes out through Resend, and analytics run on PostHog with no advertising trackers.

Why your answers are low-sensitivity by design

The most security-relevant thing we hold is a set of yes/no/unsure answers about whether recognised controls are in place. We treat those as confidential and protect them that way. Still, they are a summary of your posture, not a map of your systems. We hold no IP addresses, software inventories, configurations or vulnerabilities.

What we are not

Veritas Cyber is not a certification body, auditor, scanner, or monitoring service, and nothing it produces is legal, insurance or financial advice. Your documents record what you tell us about your own business. We say this on every key page on purpose. A tool that is clear about its limits is easier to trust, and we'd rather you knew exactly what you're getting.

Questions

Questions about how we handle data? Email hello@veritas-cyber.com. If you're a broker or MSP weighing us up for your clients, see Partners.