Security & data handling
Staging-first evaluation, minimum access, synthetic or sanitized data, and engagement-specific artifact controls.
Trust center
Current controls, explicit limitations, and the documents a buyer needs before sharing workflow context or granting bounded access.
Current posture
Verune is an early founder-led practice. These materials describe implemented controls and operating commitments; they do not claim SOC 2, ISO certification, regulatory approval, or accredited conformity assessment.
Staging-first evaluation, minimum access, synthetic or sanitized data, and engagement-specific artifact controls.
What the application collects, why it is used, how long it is kept, and how to request deletion.
The current browser-tracking posture and a named register of infrastructure providers.
A dedicated security contact and machine-readable security.txt file for responsible reports.
Buyer review path
Read the security, privacy, cookie, and subprocessor materials before submitting sensitive workflow context.
Agree the environment, allowed data, account permissions, artifact recipients, and deletion expectations.
Use the MSA, statement of work, and DPA as review materials; final terms require both parties' approval.
Confirm access revocation, evidence delivery, and artifact deletion at engagement close.
Next step
Bring security, privacy, and procurement questions into the fit review so the sprint can be scoped honestly.