SECURITY OVERVIEW / EFFECTIVE JULY 22, 2026
Minimize. Isolate. Fail closed.
Verahelm reduces exposure by limiting accepted data, retaining no API payloads by default, separating public access from proprietary processing, and revoking access when authoritative security state is uncertain.
Control principles
- Passwordless, short-lived, single-use access verification and revocable server-side sessions.
- High-entropy, scoped, expiring API keys stored only as protected verification values.
- Strict route, method, media-type, schema, size, rate, quota, and geographic boundaries.
- Private proprietary processing separated from public interfaces.
- Encryption, least privilege, metadata-only operational records, centralized redaction, and emergency disable controls.
- Hosted payment collection when enabled; Verahelm does not receive card or bank credentials.
Customer responsibilities
Protect email access and API keys, use least privilege, follow the published input boundary, keep secrets out of client code and repositories, independently validate results, and promptly revoke suspected compromised access.
Responsible reporting
Send a concise report to security@verahelm.com with the affected public route, UTC time, request ID, and safe reproduction description. Do not include credentials, keys, customer data, proprietary material, exploit payloads, or confidential attachments. Verahelm does not authorize denial of service, social engineering, destructive testing, privacy invasion, persistence, or access to another customer's data.
Disclosure boundary
To protect customers and Verahelm, public materials intentionally omit credentials, detailed topology, rule logic, thresholds, proprietary evaluation methods, and operational response procedures.