Skip to main content

04Security & trust · Under seal

Security is our product.

Verxi manages your most sensitive compliance data. We hold ourselves to the highest security standards — and prove it with our own SOC 2 Type II certification.

On the record · 2026
Vx
Redacted

AInternal control · Dogfooding

We eat our own dogfood.

Verxi is SOC 2 Type II certified. Our own compliance is managed entirely through Verxi — automated evidence collection, control mapping, and auditor sharing. When we say "automate compliance," we mean it for ourselves first. The sections that identify our own infrastructure remain redacted, exactly as they are in the report your auditor will receive.

BTechnical & organizational measures

Security controls, on the record.

CTRL-01

Encryption at Rest

AES-256-GCM

All data — evidence files, control mappings, user data, and audit logs — is encrypted at rest using AES-256-GCM. Encryption keys are managed via AWS KMS with automatic rotation every 365 days. Customer-managed keys (CMK) available on Enterprise tier.

CTRL-02

Encryption in Transit

TLS 1.3

All connections enforce TLS 1.3 with strong cipher suites (TLS_AES_256_GCM_SHA384). HSTS headers with 1-year max-age. Certificate pinning for API clients. Legacy TLS 1.0/1.1 connections are rejected.

CTRL-03

Access Control

RBAC + SSO/SAML + 2FA

Role-based access control with four tiers: Viewer, Editor, Admin, Owner. SSO via SAML 2.0 (Okta, Azure AD, OneLogin). Mandatory 2FA for all admin accounts. Session tokens expire after 24 hours with sliding window refresh. API keys scoped to read/write/admin.

CTRL-04

Audit Logging

Immutable & Tamper-Proof

Every action in Verxi — login, data access, configuration change, evidence upload, report generation — is logged to an append-only audit trail. Logs include user identity, timestamp, IP, action type, and resource. Stored in WORM (Write Once Read Many) storage with 7-year retention.

CTRL-05

Infrastructure

SOC 2 Certified Data Centers

Hosted on AWS us-east-1 and eu-west-1. All infrastructure runs in SOC 2 Type II, ISO 27001, PCI DSS, and FedRAMP certified data centers. Auto-scaling with load balancing. Database (PostgreSQL) runs in Multi-AZ configuration with automated daily snapshots and point-in-time recovery.

CTRL-06

Penetration Testing

Annual Third-Party

Annual third-party penetration testing conducted by NCC Group. Continuous vulnerability scanning via AWS Inspector and Snyk. Bug bounty program via HackerOne (public). All critical/high findings remediated within 48 hours. SOC 2 auditor has full access to pen test reports.

CTRL-07

Compliance Certifications

SOC 2, ISO 27001, GDPR, HIPAA

Verxi maintains SOC 2 Type II certification (audited by BDO), ISO 27001:2022, and GDPR compliance. We are also compliant with HIPAA (BAA available on request), CCPA, and PIPEDA. We eat our own dogfood — Verxi runs on Verxi.

CTRL-08

Data Residency

US, EU, APAC Regions

Choose where your data lives. Available regions: US (Virginia), EU (Frankfurt), APAC (Singapore). Data never leaves your selected region. EU customers can opt for EU-only processing to satisfy GDPR Art. 44-49 requirements. Data residency proof available in-app.

CRegistrations · Current posture

Our compliance posture.

SOC 2 Type IISealedSince Sept 2024
ISO 27001:2022SealedSince March 2025
GDPRCompliantDay one
HIPAACompliantBAA on request
CCPACompliantDay one
PCI DSSN/A

DProcedure · Incident response

When something happens, we tell you.

We maintain a documented incident response plan tested quarterly. In the event of a security incident affecting customer data, we commit to:

01Notification within 24 hours of confirmed breach
02Detailed root cause analysis within 72 hours
03Remediation timeline communicated proactively
04Post-incident report shared with affected customers
05SOC 2 auditor notified per contractual obligations

Need our SOC 2 report?

Request our SOC 2 Type II report or security questionnaire response. Available under NDA.