Skip to content
Verity Audit

Security

Security built for the sensitivity of audit work

Internal audit findings, working papers and risk assessments are some of the most sensitive records an organisation holds. Verity is built with defense-in-depth so your team can trust the platform with that responsibility.

Strict multi-tenant isolation

Every organisation on Verity is isolated at the data layer. Application-level tenant scoping ensures no engagement, working paper, issue or report is ever visible to another organisation — your audit data is yours alone.

Two-factor authentication

Accounts can be protected with time-based one-time-password (TOTP) two-factor authentication, reducing the risk of account takeover even if a password is compromised.

Encryption at rest and in transit

Data is encrypted at rest in the database and object storage, and every connection to Verity is encrypted in transit over HTTPS/TLS. There is no unencrypted path to your audit data.

Hardened file uploads

Evidence and attachments pass through content-type validation, size limits and storage isolation before they are stored, reducing the risk that a malicious upload could affect the platform or other tenants.

Least-privilege access control

Role-based permissions govern what each user can see and do, scoped down to individual engagements where appropriate. Administrative actions are limited to the people who need them.

Independent, adversarial security review

Verity's codebase and infrastructure are reviewed with an adversarial mindset — actively looking for the ways access controls, tenant isolation or input handling could be broken — rather than relying on a single self-assessment.

Our approach, honestly stated

No system is unhackable, and we won't claim otherwise. What we can commit to is a defense-in-depth approach: multiple independent layers of protection — isolation, authentication, encryption, input hardening and access control — so that no single failure exposes your data. We treat security as an ongoing practice, not a one-time checklist, and we welcome scrutiny of that approach rather than asking you to take it on faith.

If you have a security question we haven't answered here, or you'd like more detail for your own vendor risk assessment, we're happy to talk it through.

Have a security question before you sign up?

Talk to us directly, or start free and see the platform for yourself.