Security we practice, not just preach
We ask clients to trust us with their most sensitive systems and findings. That trust has to be earned in how we run our own shop. This page sets out how to report a weakness in verrou’s systems, how we protect the data you share with us, and where we stand on credentials and encryption.
Found a weakness in our systems? Tell us.
Security researchers make the whole ecosystem safer. If you have discovered a vulnerability in a verrou website, application, or service, we want to hear from you — and we will work the issue in good faith.
How to report
Email a description of the issue to security@verrou.ai. Include the affected asset (URL, host, or endpoint), the steps to reproduce, and any proof-of-concept material. For anything sensitive, please encrypt your report with our security PGP public key. Our machine-readable policy lives at /.well-known/security.txt.
What we ask of you
Give us reasonable time to investigate and remediate before any public disclosure. Do not access, modify, or exfiltrate data that is not yours, degrade our services, or run automated scans that disrupt other users. Stay within the scope of your own test account wherever possible. Acting in good faith along these lines, we will not pursue or support legal action against you.
Our commitment back to you
We aim to acknowledge every valid report within 1 business day.
We validate and assess severity, and keep you updated on our findings as the investigation progresses.
We remediate confirmed issues on a timeline driven by severity, and credit reporters who want recognition.
How we protect your data during an engagement
Penetration test results and cryptographic inventories are a roadmap to your weakest points. We handle that material with the same discipline we expect our clients to apply — least privilege, strong encryption, and a defined end-of-life for everything we hold.
| Practice | How we do it |
|---|---|
| Encryption in transit | All data exchanged with clients and moved between our systems travels over modern TLS. Sensitive deliverables and evidence are additionally encrypted at the file level before they leave our hands. |
| Encryption at rest | Client data, findings, and evidence are stored on full-disk-encrypted endpoints and encrypted storage. |
| Least-privilege access | Only the practitioners assigned to your engagement can access your data. Access is scoped per project, requires multi-factor authentication, and is revoked when the engagement closes. |
| Segregation | Each client’s data is kept logically separated so that findings, credentials, and evidence never mix across engagements. |
| Defined retention | We keep engagement data only as long as needed to deliver and support the work. Our standard retention period is 30 days after the final invoice is paid, unless a contract specifies otherwise. |
| Secure deletion | At the end of the retention window we securely destroy client data and evidence, and we can provide written confirmation of deletion on request. |
Have a specific requirement — a data processing agreement, a regional storage constraint, or a shorter retention window? We can accommodate most requests. Talk to us before the engagement starts.
Send us encrypted email
For sensitive correspondence — vulnerability reports, scoping details, credentials, or findings — encrypt your message to us with PGP. It is a simple step that keeps the contents of your email confidential in transit and at rest on mail servers along the way.
Our public keys
We publish a separate key per address. Encrypt general correspondence to hello@verrou.ai with our general public key, and vulnerability reports to security@verrou.ai with our security public key.
Our disclosure policy and key location are published at /.well-known/security.txt.
The absence of things is also a security posture
Every claim below is a decision we made and can point at in configuration — not an aspiration. If any of it stops being true, this page changes.
No analytics, tracking, or cookies
We run no analytics and set no cookies of any kind. Every asset — fonts included — is served from our own infrastructure, so no third party observes your visit. There is no consent banner because there is nothing to consent to.
No request logs, no IP retention
Our web server writes access logs to /dev/null. The contact form holds your IP in memory only, long enough to rate-limit abuse, and never writes it to a file, to the notification email, or to any log.
No US providers
This site runs in Iceland and our email in Switzerland. Neither country belongs to the Fourteen Eyes arrangement, and both sit inside the EEA or under an EU adequacy decision — so nothing we hold requires Standard Contractual Clauses.
No third-party form processor
The contact form is our own software running on our own server. What you type reaches us directly, with no form-as-a-service vendor sitting in the middle holding a copy.
No junior bench, no handoffs
The senior practitioner who scopes your engagement is the one who performs the work and writes the report. Nobody is handed to a trainee once the contract is signed.
No security theater
We don’t issue assurances we aren’t entitled to issue, and we say so when an engagement isn’t worth running. Every service datasheet names the situations where we are the wrong choice.
A straight answer about US law
The CLOUD Act reaches providers of communication and remote-computing services. We are a consultancy, not a provider, and the providers we do use are Icelandic and Swiss — so that route to your data is closed.
What we will not pretend: verrou, Inc. is a US company, and a US court can compel a US company to produce what it holds, wherever it is stored. That is ordinary jurisdiction, not the CLOUD Act, and it applies to every US-incorporated consultancy regardless of where its servers sit. Our answer is architectural rather than rhetorical — we hold as little as possible. No request logs, no IP addresses, no analytics, and engagement material deleted on a defined schedule. A demand can only reach what exists.