SECURITY & COMPLIANCE

Security review for governed AI messaging.

Verbum is built for teams that need AI-assisted messaging with human approval where required, traceability, privacy-aware workflows and documented security controls across business channels.

Security explains the technical and operational controls. The Trust Center maps available evidence, scope and qualified-review paths.

Public control overview

Technical and operational controls for governed AI messaging.

Verbum is built for teams that need controlled AI workflows, traceable messaging, access controls and qualified security review without exposing sensitive evidence publicly.

Public control overview

Public controls cover RBAC, least privilege, tenant separation, encrypted transport, storage protection where applicable, incident response, credential handling and AI data handling.

Type
Public technical and operational control summary
Availability
Public overview; implementation detail is handled through qualified review.

This page summarizes public controls. Evidence status, scope and availability are maintained in the Trust Center and shared through qualified security review.

Independent evidence

Trust Center is the source of truth for reports, certificates and testing references.

Security lists the public posture. Trust Center owns evidence names, status, evidence type, approved metadata and availability so sensitive materials are not duplicated across pages.

Evidence in Trust Center

SOC 2 Type II report

Status
Qualified review material
Owner
Security / Compliance
Evidence type
SOC 2 Type II report
Availability
Available to qualified customers during security review, subject to NDA or an appropriate confidentiality process.
Confidentiality
Subject to NDA or an appropriate confidentiality process.
Review in Trust Center

Evidence in Trust Center

ISO/IEC 27001:2022 evidence review

Status
Qualified review material
Owner
Security / Compliance
Evidence type
Information security management evidence
Availability
Available to qualified customers during security review, subject to NDA or an appropriate confidentiality process.
Confidentiality
Subject to NDA or an appropriate confidentiality process.
Review in Trust Center

Evidence in Trust Center

LGPD + GDPR privacy program

Status
Qualified review material
Owner
Privacy / Legal
Evidence type
Privacy program and processing documentation
Availability
Available through qualified privacy or legal review.
Review in Trust Center

Evidence in Trust Center

Application security controls aligned with OWASP ASVS

Status
Qualified review material
Owner
Security / Compliance
Evidence type
Application security control alignment
Availability
Available to qualified customers during security review, subject to NDA or an appropriate confidentiality process.
Confidentiality
Subject to NDA or an appropriate confidentiality process.
Review in Trust Center

Evidence in Trust Center

Penetration testing review materials

Status
Qualified review material
Owner
Security / Compliance
Evidence type
Protected penetration testing review material
Availability
Available to qualified customers during security review, subject to NDA or an appropriate confidentiality process.
Confidentiality
Subject to NDA or an appropriate confidentiality process.
Review in Trust Center

Qualified review materials

Security review and procurement support.

Security and privacy review materials are available through qualified review.

Materials available for review

  • Vendor questionnaires and RFP responses
  • Data Processing Overview review
  • Subprocessors review
  • Procurement documentation
  • Security and privacy review materials for qualified reviews

Workflow security

How security maps to Verbum workflows.

Security in Verbum is tied to configured workflows: who can access a workspace, how permissions are scoped, how credentials are handled and how enabled workflow events can support later review.

Workflow controls

  • Role-based access controls are designed to limit drafting, review, approval and administration to authorised workspace roles. Applies where enabled, within approved implementation scope, and during qualified review.
  • Least-privilege access is applied to workspace roles, operational access and approved integration onboarding where applicable. Applies where enabled, within approved implementation scope, and during qualified review.
  • Enabled workflow events can be recorded with available message, reviewer, rule, channel and timestamp context, subject to workspace configuration, plan capabilities and provider support. Applies where enabled, within approved implementation scope, and during qualified review.
  • Channel, API and integration credentials are handled through protected setup, scoping, rotation or revocation practices where applicable. Applies where enabled, within approved implementation scope, and during qualified review.

Data protection controls

Data protection claims stay bounded by scope.

Security controls for tenant separation, transport protection, storage protection, retention and incident handling are described at a public level here. Detailed implementation evidence is handled through qualified security review.

Mapped data protection controls

  • Workspace-scoped access patterns are designed to keep tenant data separated across messages, contacts, credentials and audit records. Applies where enabled, within approved implementation scope, and during qualified review.
  • Browser and API connections are designed to use encrypted transport; protocol details can be reviewed during security evaluation. Applies where enabled, within approved implementation scope, and during qualified review.
  • Encryption at rest is documented where applicable for platform storage and reviewed through qualified security materials. Applies where enabled, within approved implementation scope, and during qualified review.
  • Verbum operates a documented incident response process for detection, containment and customer notification where applicable. Applies where enabled, within approved implementation scope, and during qualified review.
  • Retention and deletion are reviewed through workspace configuration, plan policy, provider configuration, DPA, order form or written agreement. Applies where enabled, within approved implementation scope, and during qualified review.

AI governance

AI with governance, not a black box.

Verbum Sense, Verbum Assist and Verbum Automate are designed around configured context boundaries, human review where required, policy-based automation and the shared AI data handling policy.

See approval workflows

AI drafts and routes messages inside the controls your team configures.

  • AI context is designed to stay scoped to the active workspace conversation, configured policy context and selected channel metadata. Applies where enabled, within approved implementation scope, and during qualified review.
  • Verbum Automate can act only when configured policy and guardrails match the message context. Applies where enabled, within approved implementation scope, and during qualified review.
  • Customer operational data is not used for Verbum marketing.
  • Verbum does not use customer business messages to train public AI models unless explicitly stated and contractually allowed.
  • Customer message content is processed to provide configured AI-assisted drafting, routing, review and Verbum Automate workflows.
  • Customer message content is not used to train public or general-purpose AI models unless explicitly stated and contractually allowed.
  • Fine-tuning or training on customer message content requires explicit written authorization in the applicable agreement.
  • AI subprocessors may process prompts, message context and outputs only to provide the configured service, subject to applicable provider terms and approved customer configuration.
  • Retention of prompts, outputs and related workflow context follows the applicable workspace settings, plan terms, provider configuration, DPA, order form or written agreement.