Trust / Security
Security at Vera.
Last updated August 11, 2026
Principles
Vera is being designed around least-privilege access, isolated processing, encryption in transit, and customer-controlled changes. Product access is read-only unless you explicitly request a fix, and fixes are proposed through pull requests for your review.
Payments
Early-access payments are processed by Stripe Checkout. Vera does not receive or store full card numbers.
Source code
Vera will not use customer source code to train general-purpose models without explicit permission. Detailed retention, deletion, subprocessors, and access-control terms will be provided before private-beta repository access is enabled.
Current status
Vera is in private beta. We do not currently claim SOC 2, ISO 27001, or other third-party security certification. We will publish verified assurance information here as it becomes available.
Report a vulnerability
Please report suspected security issues privately to team@reefincorporated.com. Include enough detail for us to reproduce the issue. Do not access other users’ data, disrupt service, or publicly disclose an unresolved vulnerability.