Trust / Security

Security at Vera.

Principles

Vera is being designed around least-privilege access, isolated processing, encryption in transit, and customer-controlled changes. Product access is read-only unless you explicitly request a fix, and fixes are proposed through pull requests for your review.

Payments

Early-access payments are processed by Stripe Checkout. Vera does not receive or store full card numbers.

Source code

Vera will not use customer source code to train general-purpose models without explicit permission. Detailed retention, deletion, subprocessors, and access-control terms will be provided before private-beta repository access is enabled.

Current status

Vera is in private beta. We do not currently claim SOC 2, ISO 27001, or other third-party security certification. We will publish verified assurance information here as it becomes available.

Report a vulnerability

Please report suspected security issues privately to team@reefincorporated.com. Include enough detail for us to reproduce the issue. Do not access other users’ data, disrupt service, or publicly disclose an unresolved vulnerability.