VERAHELMSECURITYSECURITY CONTACT ↗

SECURITY OVERVIEW / EFFECTIVE JULY 22, 2026

Minimize. Isolate. Fail closed.

Verahelm reduces exposure by limiting accepted data, retaining no API payloads by default, separating public access from proprietary processing, and revoking access when authoritative security state is uncertain.

NO ABSOLUTE SECURITY CLAIM. Security controls reduce risk but cannot guarantee an incident-free, uninterrupted, or error-free service.

Control principles

Customer responsibilities

Protect email access and API keys, use least privilege, follow the published input boundary, keep secrets out of client code and repositories, independently validate results, and promptly revoke suspected compromised access.

Responsible reporting

Send a concise report to security@verahelm.com with the affected public route, UTC time, request ID, and safe reproduction description. Do not include credentials, keys, customer data, proprietary material, exploit payloads, or confidential attachments. Verahelm does not authorize denial of service, social engineering, destructive testing, privacy invasion, persistence, or access to another customer's data.

Disclosure boundary

To protect customers and Verahelm, public materials intentionally omit credentials, detailed topology, rule logic, thresholds, proprietary evaluation methods, and operational response procedures.