Trust & data handling
Last updated: 18 July 2026
You're considering telling a security product about your security. That deserves a straight explanation of what we hold, what we deliberately don't, and why the product is built the way it is.
The design principle: hold less
Veritas Cyber is a self-assessment and document-generation tool. You answer plain-English questions about your own controls; we score them against published frameworks and generate your documents. That design means we simply don't need — and don't build features that would need — the sensitive things a security vendor might otherwise hold.
What we never collect
- No credentials or secrets. We never ask for passwords, API keys, or access to any of your systems.
- No scanning or agents. Nothing is installed on your devices and we never connect to, probe, or monitor your network. There is no telemetry from your environment because nothing of ours runs in it.
- No customer data of yours. Your answers describe your practices (“we back up daily”) — they never include your customers' records.
What we do hold
- Free assessment: your answers stay in your browser. If you ask us to email your snapshot, we store your email address and the level summary — not your individual answers.
- With an account: your email, business details (name, industry, staff count), and your saved self-reported answers and results — the minimum needed to generate and refresh your documents.
- Payments: processed by Stripe. We never see or store card details.
The full detail, including retention and your rights, is in our Privacy Policy.
Where it lives
Account data is stored with Supabase (Postgres) with row-level security, so your data is only readable by your authenticated account. Documents are generated on demand from your answers and downloaded to you — we store a log of what was generated, not a library of your PDFs. Email is sent via Resend; analytics run on PostHog with no advertising trackers.
Why your answers are low-sensitivity by design
The most security-relevant thing we hold is a set of yes/no/unsure answers about whether recognised controls are in place. We treat that as confidential and protect it accordingly — but it is deliberately a summary of posture, not a map of your systems: no IP addresses, no software inventories, no configurations, no vulnerabilities.
The boundaries we state everywhere
Veritas Cyber is not a certification body, auditor, scanner, or monitoring service, and nothing it produces is legal, insurance, or financial advice. Your documents record your own attestations. We think a tool that knows its boundaries is a safer tool to trust — that boundary-keeping is the product.
Questions
Ask us anything about data handling at hello@veritas-cyber.com. If you're evaluating us for a client book as a broker or MSP, see Partners.