Verifort
Security

Built by someone who has had to answer for a breach.

You are buying software that will hold your policies, your audit findings and your incident records. Here is exactly how it is built, in enough detail that your auditor can evaluate it.

Your data is in your own database

Not a shared table with a customer ID column. Each organization gets its own database and its own application instance. There is no query anywhere that could return another customer's records, because the data is not there to return.

Permissions enforced on the server

Every page and every background call checks what you are allowed to do before it does anything. Hiding a button is not security; the check happens where it cannot be bypassed.

Everything is written down

Who changed a policy, who approved an exception, who viewed a sensitive case, who signed in and from where. The audit trail is the product, not an add-on.

Nothing is pooled between customers

Every assisted feature reads only your organization's own records. Nothing is shared between customers, and your content is never used to improve anything outside your own system.

The specifics

  • Passwords stored with PBKDF2-SHA256 at 600,000 iterations, per current OWASP guidance — never recoverable, not even by us
  • Account lockout after repeated failures, plus per-address rate limiting on sign-in and password reset
  • Every database query parameterized. No user input is ever concatenated into SQL
  • All output encoded; rich text sanitized on the way in, not just on the way out
  • Uploaded files verified by their actual contents, not their file extension
  • Content Security Policy, strict transport security, clickjacking and MIME-sniffing protections on every response
  • Cross-site request forgery blocked at the application level on every state-changing request
  • Error messages never leak internals — your users see plain language, your logs keep the detail
  • Hosted on AWS with encrypted storage, automated backups and point-in-time recovery

Independent review

We will provide our architecture documentation and answer a security questionnaire as part of procurement, at no charge. If your insurer or your state requires a third-party penetration test before you can buy, tell us early and we will work with you on it.

Questions your IT contractor will ask?

Send them to us directly. We would rather have the technical conversation than have you guess.

Ask a security question