← Back to homepage

Security & Trust

Built for environments where trust is a requirement.

VRFY combines independent assurance, security controls, traceable workflows and flexible deployment options to support organisations responsible for sensitive operational information.

Independent assurance

Evidence that can be examined.

VRFY has completed SOC 2 Type II assurance, is ISO/IEC 27001 certified and its ISO/IEC 42001 certification is in process. These statements reflect the current, approved position for public use.

SOC 2 Type IIIndependent assurance completed.
ISO/IEC 27001Information security management system certified.
ISO/IEC 42001AI management system certification in process.

Security & encryption

Protect information at rest and in transit.

Platform controls include AES-256 encryption at rest and TLS 1.2 or higher for information in transit.

Access control

Limit access according to role and responsibility.

Multi-factor authentication, role-based access control and Azure AD integration support controlled access to sensitive information and workflow activity.

Auditability

Keep material activity visible and traceable.

Immutable audit logs, cryptographically chained records and workflow traceability provide a record of how information was handled and reviewed.

Environment isolation

Support organisations that require greater separation.

Dedicated customer environments are available for organisations handling sensitive operational information. Deployment requirements are evaluated for the organisation, jurisdiction and operating environment.

Deployment

Match the infrastructure to the operating environment.

Deployment requirements are evaluated according to the organisation, jurisdiction, security posture, data residency obligations and operating environment.

CloudSecure, AWS-native infrastructure with regional deployment options.
DedicatedIsolated customer environments for organisations requiring greater separation.
On-PremisesDeployment within the customer’s own environment where cloud infrastructure is not appropriate or permitted.

CRTFY™

Tamper-evident verification and digital chain of custody.

CRTFY is designed to identify unauthorised changes and preserve a verifiable record of integrity across the evidentiary workflow.

Request a Demo

See how VRFY fits your environment.

Discuss your workflow, security requirements and operating environment with the VRFY team.

Request a Demo