The moment you put Vera AI in front of a client, their security team’s verdict lands on your reputation before it lands on ours. This page gives you the whole security story the way you will need it in that room: what we enforce, what we hold, what we do not have yet, and where to send their security team so the review runs on evidence instead of assurances.
Every claim below is written so a security engineer can challenge it, and the full detail lives on the security page.
Every tenant’s rows are protected by Postgres row level security, so isolation holds at the database layer rather than in application code, and it is tested with real cross organization read attempts. In a live review we demonstrate the cross tenant read failing in front of your client’s team. This matters twice for a partner: your clients are isolated from the world, and from each other.
Data is encrypted at rest and in transit. Contract files live in private storage and are served only through short lived signed URLs, never public links. Credentials for connected tools are sealed with AES-256-GCM with a fresh initialization vector per value, shown masked, and checked for tampering. No secret is stored in our code.
MFA, SSO and SCIM for enterprise identity, and role based access inside each workspace, including the seats your consultants hold by client invitation. Platform admin status on our side lives in its own protected table a customer can never self assign, admins require multifactor, and every view and download of a contract file is written to an audit log with the actor, action, entity, organization, and IP address.
Client data stays in the client’s tenant and never feeds the cross customer benchmark pool by default; the Outcome Network contribution layer is opt in, anonymized, and protected by an anonymity floor. Exports cover contracts, reports, and deliverables. The hard delete path removes database records and stored files, with deletion certification available for compliance processes that require evidence.
The partner portal gives your firm a client book and white label invitations. Your client’s security team will ask exactly what that lets you see, so here is the boundary, stated the way we state it to them.
Contract and agreement dates: terms, renewal stages, notice deadlines, and auto renewal flags, plus workspace level engagement signals such as how many members were active this month. Enough to run the renewal motion, nothing more.
Client files, prices, benchmark results, spend, or the identities of individual members. The portal reads through narrow projections built for exactly these fields, and the partner to client link is re verified on every request. A partner seat inside the workspace exists only by the client’s own invitation.
White label invitations are single use, expire after 30 days, and are stored only as hashes. Accepting one provisions the client’s own tenant, owned by them from the first minute; the partner’s brand appears as a served by mark, never as access. The client’s workspace owners are notified when the link is made.
You cannot afford to overclaim in front of a client, so neither do we. SOC 2 Type I is targeted for Q4 2026: the controls are implemented and mapped to evidence today, and the report will be available under NDA when issued. Until then, the evidence lives in an NDA gated Trust Center and in the parts of the platform a client’s own team can verify alone in a trial tenant.
The security review package includes a section titled what we do not have yet, stated plainly, because a vendor that admits its gaps is a vendor whose claims you can believe. If your client’s procurement gate requires a certification we do not yet hold, we will tell you in week one, not in week eleven.
Deals in banking, defense, healthcare, and the public sector are usually won or lost on deployment, not features. Raise it early; the full comparison is on the deployment options page.
The standard multi tenant platform on encrypted managed cloud infrastructure. Upload today, benchmark today. Right for most clients, and the fastest path to a first result.
A single tenant instance where nothing is shared, not even the database. For clients whose policy rules out shared infrastructure but allows managed hosting.
Contract files never leave the client’s own network, and benchmarks still work. For clients whose red line is document custody rather than SaaS itself.
The full platform deployed inside the client’s own boundary. The heaviest option, for the environments where nothing else will pass review.
We complete the questionnaire, walk the architecture, and show the cross tenant read failing live. You take the credit.