The security overview your review needs.
Most of a vendor questionnaire exists to find out where your data goes and who can read it. With Verillian the answers are short: it stays with you, and only you. Here's that posture in the order a reviewer works through it, with the deeper documents linked.
Who holds the keys?
You do, and that one fact settles half the questionnaire. Signing happens on the device, content seals under your institution's key, and we can't read what we never receive.
Audit content is encrypted under a key your institution generates and holds. Opening the record takes that private key, which never reaches us, and the exact algorithms are written up in the security model for your cryptographer to check.
Each captured interaction is signed by the device that produced it, with a key that never leaves that device. The admin server can verify a signature but never mint one, which is what makes attribution stick.
Because the keys are yours, generation, custody, rotation, and recovery are yours too. We give your security team the operational guidance for running them in your own deployment.
Under any legal demand, the most the admin server could surrender is ciphertext. We can't decrypt your content for anyone, ourselves included, because the key was never ours to hold.
- prev0000000000000000000000000000000000000000000000000000000000000000record 0001 / prompt decided / ALLOWALLOWhashde70735cec5245919d1a77a20b07deaf29f204f73d3abda37dd70713af2e6c8a
- prevde70735cec5245919d1a77a20b07deaf29f204f73d3abda37dd70713af2e6c8arecord 0002 / prompt decided / REDACT / 1 token hiddenREDACThash5b54ebd8ce4f7efc059f4a46d18e33ce4c4c2c52f5d69e63680caf2e245d0ba5
- prev5b54ebd8ce4f7efc059f4a46d18e33ce4c4c2c52f5d69e63680caf2e245d0ba5record 0003 / tool call refused / BLOCKBLOCKhash101ac285e576be6e38a01d865ca8b05e7a4c2f0bd37c56ba5ad8d4de9a6de0f2
Where does your data live?
Inside your boundary, full stop. Self-hosted means the deployment is yours, and the only data we hold ourselves is the business-contact information it takes to run our own company.
The checkpoint, the admin server, and the sealed record all run on infrastructure you operate. Your prompts, responses, and tool calls are never sent to us, from any deployment, for any reason.
Everything works with no outbound connection to us at all, so an isolated network gets the same enforcement and the same record as a connected one.
The limited business-contact and website data we do hold is processed by US-based providers, and we'll share the current provider list with your review on request.
Attestation, DPA, and BAA.
Here's where we stand on paper, said straight: what we align to, what we don't yet hold, and the agreements a regulated buyer can have on request.
We don't hold a SOC 2 attestation yet, and we'd rather tell you that than imply otherwise. Self-hosting narrows what an attestation would cover, since your sensitive data never passes through us, and when we hold one, this page will say so.
If your institution needs a DPA, a draft is ready for your counsel's review today, and it's finalized with you before signature. Your deployment data never flows to us, so the processing it governs is limited to business-contact information.
We never receive protected health information from your deployment, so under the self-hosted model you may not need a BAA at all. If your counsel wants one anyway, a draft is available for review on request.
aligned, not certified / SOC 2: not yet
Availability, support, and incidents.
Your enforcement never routes through us, which retires most availability risk before it starts. What's left is how support, updates, and incidents work, so here it is.
Policy enforcement and audit capture run on your infrastructure with no Verillian service in the request path, so your control keeps working even when we don't. The status page explains why our uptime isn't your problem.
Support tiers, response targets, and our update commitments live in your agreement, and we'll walk your procurement team through the current terms before you sign anything.
We publish security updates for the checkpoint and the admin server, and you apply them on your own schedule, inside your own change process.
If an incident affects data we hold, we notify affected institutions without undue delay. Because your deployment data stays with you, an incident on our side can't expose data we never had: your prompts, your responses, and your record stay where they live, with you.
The deeper documents.
Four reads take a reviewer from posture to proof. A completed security questionnaire and the current service-provider list are available on request as well.
Architecture and data flow
Follow a request from the device, through the ruling, into the sealed record, with what crosses each boundary marked.
Read the PDFTrust and security overview
The one document to attach to a security questionnaire: posture, keys, and data flow in a single read.
Read the PDFThe full security model
The six properties enforced by construction, from fail-closed to key isolation, with what each one buys your review.
See the security modelCompliance mappings
Framework by framework, what Verillian lines up with, and the control-by-control detail on request.
See the mappingsHand this page to your security team.
We'll add the completed questionnaire, the provider list, and the mappings for your frameworks. And once they've read it all, the demo is where the architecture stops being a diagram.