Security

Designed for data that has to be defensible.

Investor onboarding data is among the most sensitive information a fund holds. VeriVest treats isolation, access control and auditability as structural requirements.

Controls

Security controls in the platform design.

Multi factor authentication

MFA is part of the account model for platform users, accountants and applicants, not an optional add on.

Role based access

Permissions follow defined roles — from organisation owner through to read only auditor — so people see only what their role requires.

Tenant data isolation

Every record is scoped to a client organisation and enforced at the database level with row level security.

Encryption in transit and at rest

Data is encrypted in transit and at rest across the application, database and document storage.

Secure document storage

Documents are never served from public URLs. Access is authenticated and time limited on every request.

Audit logging

Authentication, record changes, uploads, downloads, verification events, approvals, overrides and exports are all recorded.

Restricted administrator access

Administrative capability is separated from ordinary use and is itself logged and reviewable.

Configurable retention

Each organisation can configure how long onboarding records and documents are retained.

Regular backups

Database and document backups are taken on a regular schedule with restoration procedures.

Incident response

Defined procedures for identifying, containing, assessing and notifying on security incidents.

Privacy by design

Data collection is scoped to the onboarding purpose, with requirements configurable per organisation.

Vendor security reviews

Third party providers are assessed before integration and reviewed on an ongoing basis.

Audit logging

What gets recorded.

Audit records exist so a decision can be reconstructed later — who did what, when, and on which record.

  • Authentication
  • Application updates
  • Document uploads and downloads
  • Verification events
  • Screening events
  • Accountant invitations
  • Accountant changes
  • Signatures
  • Approvals
  • Rejections
  • Overrides
  • Role changes
  • Data exports

What we do not claim

VeriVest does not hold SOC 2 or ISO 27001 certification, and makes no claim of AUSTRAC approval, regulatory endorsement or government accreditation. This page describes controls in the platform's design. Any future certification will be published here with evidence.

Reporting a vulnerability: please contact us so we can assess and respond. We ask that issues are reported privately before any public disclosure.