Skip to content
VerifAIer
Home / Trust Center
Trust

Trust Center.

How VerifAIer earns trust: security, privacy and responsible AI in one place.

Directory

Disclosures, policies and terms.

Six documents, each reachable from here and each maintained in its own right. This page routes to them and states what is verifiable; it does not restate them.

Security

Local-first, tamper-evident and air-gap capable by design.

Security

Privacy

We hold almost nothing. Your operational data never leaves your perimeter.

Privacy

Data processing

Because it is local-first, VerifAIer processes no customer operational data.

Details

Responsible AI

Evidence over opinions, explainable results, human oversight.

Approach

Compliance

Coverage mapped to EU AI Act, NIST AI RMF and ISO/IEC 42001.

Compliance

Terms

The terms governing use of the website and platform.

Terms
Deployment model

Where VerifAIer runs, and what it can reach.

The security story starts with topology. Most questions reviewers ask are answered by where the software sits rather than by a policy document.

  • Your host or VPCyou operate it
  • Reverse proxyyour TLS, your limits
  • VerifAIer APIself-hosted process
  • Your databaseyour storage
  • Your AI provideronly if you configure one

Self-hosted by default

It runs as a container or a plain process on infrastructure you control. There is no managed control plane to depend on and no account to create.

No telemetry

The software does not phone home. Nothing about your operations is reported to us, because there is nowhere for it to be reported to.

Outbound only where you ask

The only outbound calls are to an AI provider you configure. With the built-in mock provider there are none at all, which is how the published proof was produced.

Trust boundaries

What crosses a boundary, and what never does.

Operational data stays put

Prompts, responses and repository content are processed where the software runs. They are not transmitted to VerifAIer, and we operate no service that could receive them.

Evidence is referenced, not copied

When one capability reads another's record it keeps a reference. The capability that produced a fact remains the only authority on it.

Owner-scoped data stays owner-scoped

Personal and owner-private surfaces are readable by their owner. Widening that is an explicit act with its own record, never a side effect.

Secrets are masked at import

Where the product ingests material that may contain credentials, they are masked on the way in and never written to storage.

Verification needs no key

Evidence verifies offline, without connectivity and without a key held by us. An auditor can check it years later with the files alone.

Tenancy is structural

Organisation scope is derived from the authenticated session rather than accepted from a request, so a cross-tenant read is not expressible.

Architecture guarantees

What the architecture holds to, and what it will not claim.

Guarantees are only useful next to their limits, so both are listed.

Deterministic by construction

The same inputs produce the same evidence identifiers. A result that cannot be reproduced is a defect, not a variation.

Fail closed, never fail quiet

A capability that cannot answer is reported as unavailable. Missing input becomes an explicit unknown; it never becomes a pass.

No cryptographic claim

Evidence is content-addressed and tamper-evident. It is not cryptographically signed, and the site does not describe it as though it were.

No certification, no verdict

VerifAIer maps evidence to control frameworks and computes posture. It does not certify compliance, and it is not legal advice.

Every claim on this page is a property of how the system is built. Where a property depends on how you deploy it, the page says so rather than assuming your configuration.

Certification

What we are not certified for.

A trust centre that lists only what a vendor holds teaches a reader to assume the rest. The platform can generate evidence and map it to control frameworks. That is a capability of the product; it is not a certification of the company, and the two are named apart here so neither can be read as the other.

SOC 2
Not held. No report exists.
NOT HELD
ISO/IEC 27001
Not held.
NOT HELD
ISO/IEC 42001 certification
Not held. ISO/IEC 42001 appears here as a policy pack the product reads evidence against. Reading against a framework is alignment data; it is not a certificate, and it certifies neither us nor you.
NOT HELD
Published external penetration test
None. Where one is performed it will be named with its date and scope.
NOT HELD
FedRAMP, IL5 or classified-environment accreditation
Not claimed. Air-gap compatibility is a property of the architecture; accreditation is an assessment somebody else performs on a specific deployment.
NOT HELD
SSO, OIDC, OAuth or MFA
Not implemented. sso is a catalog flag with no enforcement point.
NOT HELD
Note

This list is maintained in the same pass as the Security page and says the same thing, because a disclosure that disagrees with itself across two pages is worse than one that is missing from both.

Have a security or privacy question?

We answer directly, with no gatekeeping.