Found a weakness in our systems? Tell us.

Security researchers make the whole ecosystem safer. If you have discovered a vulnerability in a verrou website, application, or service, we want to hear from you — and we will work the issue in good faith.

How to report

Email a description of the issue to security@verrou.ai. Include the affected asset (URL, host, or endpoint), the steps to reproduce, and any proof-of-concept material. For anything sensitive, please encrypt your report with our security PGP public key. Our machine-readable policy lives at /.well-known/security.txt.

What we ask of you

Give us reasonable time to investigate and remediate before any public disclosure. Do not access, modify, or exfiltrate data that is not yours, degrade our services, or run automated scans that disrupt other users. Stay within the scope of your own test account wherever possible. Acting in good faith along these lines, we will not pursue or support legal action against you.

Our commitment back to you

Acknowledge

We aim to acknowledge every valid report within 1 business day.

Triage

We validate and assess severity, and keep you updated on our findings as the investigation progresses.

Resolve

We remediate confirmed issues on a timeline driven by severity, and credit reporters who want recognition.

No bug bounty, no red tape. We do not currently run a paid bounty program, but we take every report seriously and respond to each one personally. There is no form to fill out and no legalese to sign before you reach a human — just email security@verrou.ai — encrypt it with our security PGP key if it’s sensitive.

How we protect your data during an engagement

Penetration test results and cryptographic inventories are a roadmap to your weakest points. We handle that material with the same discipline we expect our clients to apply — least privilege, strong encryption, and a defined end-of-life for everything we hold.

Practice How we do it
Encryption in transit All data exchanged with clients and moved between our systems travels over modern TLS. Sensitive deliverables and evidence are additionally encrypted at the file level before they leave our hands.
Encryption at rest Client data, findings, and evidence are stored on full-disk-encrypted endpoints and encrypted storage.
Least-privilege access Only the practitioners assigned to your engagement can access your data. Access is scoped per project, requires multi-factor authentication, and is revoked when the engagement closes.
Segregation Each client’s data is kept logically separated so that findings, credentials, and evidence never mix across engagements.
Defined retention We keep engagement data only as long as needed to deliver and support the work. Our standard retention period is 30 days after the final invoice is paid, unless a contract specifies otherwise.
Secure deletion At the end of the retention window we securely destroy client data and evidence, and we can provide written confirmation of deletion on request.

Have a specific requirement — a data processing agreement, a regional storage constraint, or a shorter retention window? We can accommodate most requests. Talk to us before the engagement starts.

Send us encrypted email

For sensitive correspondence — vulnerability reports, scoping details, credentials, or findings — encrypt your message to us with PGP. It is a simple step that keeps the contents of your email confidential in transit and at rest on mail servers along the way.

Our public keys

We publish a separate key per address. Encrypt general correspondence to hello@verrou.ai with our general public key, and vulnerability reports to security@verrou.ai with our security public key.

Our disclosure policy and key location are published at /.well-known/security.txt.

The absence of things is also a security posture

Every claim below is a decision we made and can point at in configuration — not an aspiration. If any of it stops being true, this page changes.

No analytics, tracking, or cookies

We run no analytics and set no cookies of any kind. Every asset — fonts included — is served from our own infrastructure, so no third party observes your visit. There is no consent banner because there is nothing to consent to.

No request logs, no IP retention

Our web server writes access logs to /dev/null. The contact form holds your IP in memory only, long enough to rate-limit abuse, and never writes it to a file, to the notification email, or to any log.

No US providers

This site runs in Iceland and our email in Switzerland. Neither country belongs to the Fourteen Eyes arrangement, and both sit inside the EEA or under an EU adequacy decision — so nothing we hold requires Standard Contractual Clauses.

No third-party form processor

The contact form is our own software running on our own server. What you type reaches us directly, with no form-as-a-service vendor sitting in the middle holding a copy.

No junior bench, no handoffs

The senior practitioner who scopes your engagement is the one who performs the work and writes the report. Nobody is handed to a trainee once the contract is signed.

No security theater

We don’t issue assurances we aren’t entitled to issue, and we say so when an engagement isn’t worth running. Every service datasheet names the situations where we are the wrong choice.

A straight answer about US law

The CLOUD Act reaches providers of communication and remote-computing services. We are a consultancy, not a provider, and the providers we do use are Icelandic and Swiss — so that route to your data is closed.

What we will not pretend: verrou, Inc. is a US company, and a US court can compel a US company to produce what it holds, wherever it is stored. That is ordinary jurisdiction, not the CLOUD Act, and it applies to every US-incorporated consultancy regardless of where its servers sit. Our answer is architectural rather than rhetorical — we hold as little as possible. No request logs, no IP addresses, no analytics, and engagement material deleted on a defined schedule. A demand can only reach what exists.

Security is a two-way commitment

Whether you are reporting a weakness in our systems or evaluating us to test yours, we would rather have the conversation in the open. Reach out and we will respond personally.

Get in Touch