Security

Reporting a vulnerability

There is no published reporting address yet — the domain is being registered, and an address printed here would not receive anything. If you have found something, please hold it until this page carries an address rather than sending it somewhere it cannot arrive. This page is watched; it will change.

When there is an address, every report will be acknowledged by a person, and you will be told whether it could be reproduced and what is intended. If you would like to be credited when it is fixed, say so and you will be.

Please do not run automated scans against the production service, and please do not use another organisation’s data to demonstrate a finding.

What the product does today

Stated narrowly, because a security page that overstates is worse than none. Every table carries row-level security, so one organisation cannot read another’s rows. The audit trail is append-only and hash-chained, and nothing in the application can update or delete an entry. Supplier upload links are credentials in themselves and can be withdrawn. VERDEFY loads no third-party scripts and sets no analytics cookies; the only cookies are the ones that keep you signed in.

A formal security programme, penetration-test report and sub-processor list are being prepared alongside the customer agreement. Ask for the current position rather than assuming it — see contact.

Operated by a company not yet registered — VERDEFY-PLACEHOLDER-AWAITING-REGISTRATION