Security
Encryption everywhere
TLS 1.2+ in transit and AES-256 at rest for all stored data, including scan content and results.
Least-privilege access
Production access is scoped, logged, and requires MFA. Engineers do not have standing access to customer data.
EU-hosted, DDoS-protected infrastructure
Servers run on Hetzner in Germany, sitting behind Cloudflare's network for edge-level protection against volumetric and application-layer attacks.
Vulnerability disclosure
We run a responsible disclosure program and welcome reports from independent researchers.
Verifence is a trust and safety platform — customers send us email addresses, files, and URLs to be checked for risk, which means the security of that data is core to the product, not an afterthought. This page describes the practices and controls we use to protect it.
1. Infrastructure & hosting
The Verifence web app, API, and account data are hosted on servers provided by Hetzner in Germany, keeping customer data within the European Union. Requests are proxied through Cloudflare's global network in front of that infrastructure, which gives us edge-level DDoS mitigation and a Web Application Firewall on every request.
We do not manage our own physical servers or data centers. Infrastructure is provisioned and versioned as code, which keeps environments consistent and auditable.
2. Encryption
- In transit — all traffic to the web app and API is served over TLS 1.2 or higher. Plaintext HTTP requests are redirected to HTTPS.
- At rest — account data, scan content, and scan results are encrypted at rest using AES-256.
- Secrets — API keys and credentials are hashed or encrypted; API keys are shown in full only once, at creation.
3. Access control
Access to production systems and customer data is restricted to the engineers who need it to operate the platform, is protected by multi-factor authentication, and is logged. We follow the principle of least privilege: access is granted per system, reviewed periodically, and revoked when no longer needed.
Within your own Verifence account, Team Management lets you control which teammates can view scan history, manage billing, or issue API keys.
4. Application security
- Dependencies are continuously scanned for known vulnerabilities and kept up to date.
- Code changes go through review before being deployed.
- API endpoints are authenticated with per-account API keys and rate-limited to prevent abuse.
- Customer-submitted content (files, URLs, emails) is treated as untrusted input and processed in isolated scanning workflows.
5. Data handling & retention
Scan results are retained for 90 days on the Free plan and 12 months on paid plans, after which they are automatically deleted. You can delete individual scan results or your entire account at any time. Full detail on what we collect and how long we keep it is in our Privacy Policy.
6. Sub-processors
We use a small number of vetted sub-processors to operate the platform, each bound by a data processing agreement:
- Hetzner (Germany) — server hosting for the web app, API, and stored data
- Cloudflare — CDN and DDoS protection in front of our servers
- Stripe — payment processing and subscription billing
- Clicky and Google Analytics — usage analytics
- Threat intelligence APIs — Google WebRisk, VirusTotal, URLScan.io, Spamhaus, and Barracuda, queried as part of the scanning process
See our Data Processing Addendum for the full sub-processor list and how we handle data on your behalf.
7. Incident response
We maintain an internal incident response process covering detection, containment, and remediation. If an incident affects your data, we will notify you without undue delay, consistent with our contractual and legal obligations.
8. Vulnerability disclosure
If you believe you've found a security vulnerability in Verifence, please report it to hello@verifence.io. Include enough detail for us to reproduce the issue. We ask that you give us a reasonable window to investigate and remediate before public disclosure, and that you avoid accessing or modifying other customers' data while testing.
9. Compliance
Our security program is built around the practices described on this page: encryption, least-privilege access, vetted sub-processors, and incident response. Formal third-party certifications (such as SOC 2) are on our roadmap — if your organization requires a specific certification or a completed security questionnaire as part of your vendor review, contact us and we'll work with you directly.
10. Contact
Questions about our security practices, or want to report a vulnerability?
Softway Solutions SRL (trading as Verifence)
hello@verifence.io