Governance & compliance
Information Security
Version: 2.0 · Last updated: 2026-02-24
Overview
Verca AB applies technical and organizational controls to protect customer information. This work is based on the principles of confidentiality, integrity and availability, and is governed by internal policies, risk assessments and ongoing monitoring.
Encryption
| Layer | Method |
|---|---|
| At rest | AES-256 — databases, files and backups |
| In transit | TLS 1.2 or later — all communication between client and server |
| Key management | Encryption keys are stored separately from data and rotated according to defined intervals |
Access control
- Role-based access control (RBAC) with the principle of least necessary privilege
- Tenant isolation — each organization's data is strictly separated at database level
- Sessions with defined time limits that are invalidated upon inactivity
- Internal access to production environments limited to authorized personnel with individual accounts and MFA
- SSO via SAML 2.0/OIDC for organizations with centralized identity management (Enterprise)
Data storage
Verca's primary platform data is stored within the EU/EEA. Hosting and server partners are selected based on requirements for data security, operational stability and regulatory compliance. If an organization administrator enables an AI capability, information submitted by a user to that capability may be processed by the listed AI sub-processors in the United States. Such transfers are governed by data processing agreements, EU Standard Contractual Clauses and a documented assessment under GDPR Chapter V. AI is disabled by default and can be disabled by the organization.
Backup and recovery
- Daily automated backups of all customer data
- Backups encrypted and geographically separated within the EU/EEA
- Recovery procedures tested regularly
- Defined targets for recovery time (RTO) and acceptable data loss (RPO)
Incident management
Verca AB has documented procedures for detecting, classifying, remediating and reporting security incidents. In the event of an incident affecting customer data:
- Immediate actions to limit impact
- The customer is informed without undue delay
- Reporting to the supervisory authority within 72 hours in the case of a personal data incident (Article 33 GDPR)
- The incident is documented and followed up
Security testing and monitoring
- Regular vulnerability scanning of infrastructure and application
- Periodic penetration testing
- Continuous logging and monitoring with full audit trail
- Dependencies and third-party components are reviewed and updated on an ongoing basis
Development security
Security is integrated into the development process. Production environments are separated from development and test environments.
- Code review before merging to production branches
- Automated tests as part of the delivery process
- Sensitive configuration and secrets managed via dedicated services — never in source code
- MASTERLOCK protection on security-critical files — auth, audit trail, validation and encryption cannot be changed without explicit approval
Sub-processors
External suppliers for operations, backup or other technical functions are engaged under data processing agreements. All sub-processors are reviewed for security and privacy requirements. A current list of sub-processors is available in the Data Processing Agreement (DPA).
