Security & data handling
The long version.
This page describes how Verani handles your data. It is deliberately sober: no badges, no marketing claims — only what holds.
Human approval
Verani drafts communication; sending happens exclusively after explicit approval by an authorised person. This gate is part of the architecture, not a setting. There is no operating mode in which the system communicates outward on its own.
Data residency and infrastructure
Your documents and the search indexes derived from them are held in the European Union. Ireland and Germany are available as regions; which one applies is agreed with you before implementation and recorded in writing. [CONFIRM: infrastructure provider and the contractual data-residency guarantee — enter only once contractually substantiated.]
Model providers
You decide which language model your system uses. Our current recommendation is Claude by Anthropic: its commercial terms confirm that your content is not used to train models. If you deploy a different model, we review its terms before go-live and put them in front of you. [CONFIRM: the specific contract version and plan this assurance rests on.]
Access and roles
Access follows a role model: who sees documents, who reviews drafts, who approves — your organisation decides. Every action is logged with timestamp and author.
Traceability
Every answer the system gives points to its source — document, page, clause. Every draft, every edit, and every approval is retained in a complete history.
Data processing & GDPR
A data processing agreement (DPA) and the accompanying GDPR documentation are in preparation. Until both exist we claim nothing else here — we'll tell you the current status in the conversation. We hold no certifications or audit reports, and we claim none.