Qualified review material
SOC 2 Type II report
SOC 2 Type II report
ビジネスメッセージングチャネルでAIを利用するチーム向けに、Verbumのセキュリティ体制、プライバシーへの取り組み、コンプライアンス証跡、調達リソースを確認できます。
TRUST CENTER AREAS
Start with the area your evaluator needs, then use the matrix below to confirm status, scope, issuer and availability.
Public control overview, mapped security control documentation and protected implementation detail for qualified review.
Review areaPublic documentation plus qualified legal/privacy review.Privacy Policy, Public Data Processing Overview, retention context and the legal review path for DPA questions.
Review areaPublic disclosure plus qualified review.Public provider disclosure plus protected provider-category and deployment-specific details for qualified review.
Review areaQualified review material; NDA may apply.Qualified-review material for certificates, reports, control mappings or testing evidence when issuer, dates and scope are approved.
Review areaAvailable through qualified procurement review.Questionnaire support, RFP responses, security package routing, DPA context and deployment-specific follow-up.
Review areaPublic policy.Responsible disclosure policy, permitted reporting path, safe-harbor expectations and prohibited testing boundaries.
Review areaTRUST RESOURCE MATRIX
Resources are grouped by type so Verbum-owned policies, control descriptions, qualified-review packages and independent evidence are not treated as the same thing.
Independent and qualified-review evidence
Qualified review material
SOC 2 Type II report
Qualified review material
Information security management evidence
Qualified review material
Privacy program and processing documentation
Qualified review material
Application security control alignment
Qualified review material
Protected penetration testing review material
Security and privacy review materials are available through qualified review.
| Evidence area | What it covers | Availability | Review Path | NDA Required | Related document |
|---|---|---|---|---|---|
| Security controls | Access control, tenant separation, encrypted transport, storage protection where applicable and credential handling. | Qualified review; confidentiality process may apply. | Request Security Package | May apply for detailed control materials. | Security overview |
| Privacy and DPA | Privacy Policy, Data Processing Overview, retention matrix, deletion review and AI training policy. | Public overview plus qualified legal/privacy review. | Request DPA Review | Not required for public pages; legal review may use a confidentiality process. | Data Processing Overview |
| Subprocessors | Public provider disclosure, provider categories available during qualified review and deployment-specific provider context. | Public page; additional provider details through qualified review. | View Subprocessors | May apply for protected provider or deployment-specific details. | Subprocessors |
| Compliance evidence | SOC 2 Type II report, ISO/IEC 27001:2022 evidence review, LGPD + GDPR privacy program, Application security controls aligned with OWASP ASVS, Penetration testing review materials | Qualified review material. Certificates, reports or independent assessments are referenced only when issuer, dates and scope are approved for disclosure. | Request Security Package | NDA or an appropriate confidentiality process may apply. | Security overview |
| Procurement support | Security questionnaires, RFP responses, procurement follow-up, DPA context and deployment-specific review. | Available through qualified procurement review. | Contact Procurement | May apply depending on requested materials. | Legal Center |
| Security disclosure | Vulnerability reporting scope, safe-harbor expectations, prohibited testing and security contact path. | Public policy. | Review Security Disclosure | No NDA required for the public disclosure policy. | Security Disclosure |
Security and compliance evidence source of truth
Current evidence available
control description
Current evidence available
control description
Current evidence available
qualified-review package
Current evidence available
public policy
Current evidence available
control description
Trust resource source of truth
public policy
Public terms for subscriptions, platform use, customer content and governance responsibilities.
Open resourcepublic policy
Public privacy policy describing how Verbum collects, uses and protects personal data.
Open resourcepublic policy
Public cookie and browser storage inventory with consent-control context.
Open resourcepublic policy
Public overview. It does not replace the signed DPA.
Open resourcepublic policy
Public subprocessor disclosure and qualified review path for protected provider details.
Open resourcecontrol description
Public control overview. Evidence status and sensitive materials remain handled through qualified review.
Open resourcepublic policy
Public responsible disclosure policy for vulnerability reports.
Open resourcecontrol description
Control documentation can be shared with qualified reviewers without exposing sensitive implementation details publicly.
Open resourcecontrol description
Public AI data handling summary aligned with Security, Privacy, Terms and Data Processing Overview.
Open resourcequalified-review package
Security and privacy review materials available for qualified review.
Request reviewqualified-review package
Questionnaire support can be provided during qualified enterprise review.
Request reviewqualified-review package
Available to qualified customers during security review, subject to NDA or an appropriate confidentiality process.
Request review