Trust center

Evidence about how the evaluation practice itself operates.

Current controls, explicit limitations, and the documents a buyer needs before sharing workflow context or granting bounded access.

Current posture

Transparency before certification claims.

Verune is an early founder-led practice. These materials describe implemented controls and operating commitments; they do not claim SOC 2, ISO certification, regulatory approval, or accredited conformity assessment.

01Public

Security & data handling

Staging-first evaluation, minimum access, synthetic or sanitized data, and engagement-specific artifact controls.

02Public

Privacy and retention

What the application collects, why it is used, how long it is kept, and how to request deletion.

03Public

Cookie and vendor inventory

The current browser-tracking posture and a named register of infrastructure providers.

04Public

Vulnerability disclosure

A dedicated security contact and machine-readable security.txt file for responsible reports.

Buyer review path

Move from public posture to engagement-specific controls.

01

Review

Read the security, privacy, cookie, and subprocessor materials before submitting sensitive workflow context.

02

Scope

Agree the environment, allowed data, account permissions, artifact recipients, and deletion expectations.

03

Contract

Use the MSA, statement of work, and DPA as review materials; final terms require both parties' approval.

04

Verify

Confirm access revocation, evidence delivery, and artifact deletion at engagement close.

Next step

Review the boundary before the workflow.

Bring security, privacy, and procurement questions into the fit review so the sprint can be scoped honestly.