Trust centre

Security and evidence handling

Practical controls, clear boundaries, and no unsupported certification claims.

Reviewed 17 July 2026

Application controls

Evidence boundary

HAR, log, and pasted evidence is sent to the Cloudflare application for transient processing. Raw uploads are not written to the account database by the analysis routes. The generated result is saved only after an explicit workspace action. Users should still remove tokens, cookies, request bodies, and personal identifiers before upload.

Infrastructure

The application runs on Cloudflare Pages and Workers with Cloudflare D1 and KV bindings. Transactional email is sent through Resend and subscriptions are managed through Stripe. Access credentials are stored as platform secrets rather than in public source files.

Responsible disclosure

Report a suspected vulnerability to support@veritriage.com with reproduction steps and impact. Do not access other users' data, disrupt production, or publish sensitive details before remediation. Good-faith reports will be acknowledged and prioritised based on verified impact.

Current assurance position

VeriTriage does not currently claim SOC 2, ISO 27001, PCI DSS certification for its own application, or enterprise SSO unless a signed order explicitly includes it. Stripe handles payment-card entry on its hosted pages. Security questionnaires and data-processing requirements can be submitted through the purchasing route.