SecurityYou are tellingit a lot.

So here is exactly how it is held, in plain terms, including the parts a bigger company would have and this one does not.

What is in place

How it is actually held.

Specific rather than reassuring, because reassuring is what everybody writes.

Separated at the database

Access to your rows is restricted by the database itself rather than only by the app in front of it. One account cannot read another's data even if the application were tricked into asking for it.

Encrypted, both ways

Every connection between your phone and the servers uses current TLS. What is stored is encrypted at rest, including the files you keep in the vault.

Never sold, never trained on

Not to advertisers, not to data brokers, not to anybody. What you write is not used to train any model, and there is no advertising anywhere in Vera because there are no ads.

Your card never reaches us

Subscriptions are taken by the App Store. Your card details are handled entirely by Apple and never touch anything we run, so there is nothing on our side to lose.

Very few hands

One person operates Vera. Administrative access exists because somebody has to be able to restore a backup, and it is used sparingly. Nobody is reading your entries out of interest.

Australian rules

Built and run in Melbourne, and handled under the Privacy Act 1988 and the Australian Privacy Principles. If something goes wrong there are rules about telling you, and they are followed.

What is not in place

And what this does not have.

Anybody reading a security page closely can work most of this out. Better to say it than to be caught implying otherwise.

No SOC 2 or ISO certification

Those are audits that cost more than this operation makes. If your workplace requires one before you can install something, Vera will not pass that check.

No third party penetration test yet

The app has not been formally tested by an outside security firm. That is on the list, and until it happens it would be dishonest to imply otherwise.

No security team

There is one person. That means decisions are quick and there is nobody to pass a report to, which cuts both ways.

No end to end encryption

Your data is encrypted in transit and at rest, but not in a way that makes it unreadable to us. It cannot be: the assistant has to read your week in order to answer questions about it.

The commitments

Five that will not change.

Each of these is also written into the privacy policy, which is the version that binds.

Your information is never sold, rented or traded.

What you write is never used to train a model.

There is no advertising in Vera, and no ad network anywhere near it.

Ask for a copy of everything held about you and you will be sent it.

Ask for it all to be deleted and it is deleted, not archived.

Found something?

Tell me before you tell the internet.

If you find a vulnerability, email contact@getvera.au with enough detail to reproduce it. You will get a reply, usually within a day or two, and you will be told what is being done about it.

Report something in good faith and no legal action will be taken against you for finding it. Do not access, change or delete anybody else's data while you are looking, and give a reasonable window to fix it before publishing.

There is no bug bounty. There is no budget for one. What there is, is credit if you want it and a fix that actually gets shipped, usually the same week.

Anything else you want to know?

Ask a specific question and you will get a specific answer, including where the answer is not flattering.

Get Vera free

On the App Store

Download