Security & Data Breach Policy
Version 1.0 — June 2026 — Verid (trading as Proveit)
1. Security measures
Proveit implements the following technical and organisational measures to protect personal data:
- Encryption in transit: All data transmitted between clients and Proveit servers is encrypted using TLS (Transport Layer Security).
- Encryption at rest: All data stored in Proveit databases and file storage is encrypted using AES-256.
- Row Level Security (RLS): Database-level access controls ensure that each customer account can only access its own data. Cross-account data access is prevented at the database layer.
- Access controls: Access to production systems is limited to authorised personnel. Credentials are stored securely and rotated when necessary.
- Secrets management: API keys, credentials, and other secrets are stored as environment variables and never committed to source code repositories.
2. Data breach response process
In the event that a personal data breach is discovered, Proveit will take the following steps:
- Contain the breach immediately. Access to affected systems will be suspended or restricted to prevent further exposure of personal data.
- Assess scope and impact. We will determine the nature of the breach, the categories and approximate number of data subjects and records affected, and the likely consequences.
- Notify affected Controllers within 72 hours. Customers whose data has been affected will be notified by email to their registered address. The notification will include the nature of the breach, data categories and volumes affected, likely consequences, and measures taken or planned.
- Notify the Autoriteit Persoonsgegevens within 72 hours if the breach is likely to result in a risk to the rights and freedoms of natural persons. Notifications are submitted at autoriteitpersoonsgegevens.nl/melden.
- Document the breach and actions taken. All breaches, regardless of whether notification to the supervisory authority is required, will be recorded internally including the facts, effects, and remedial actions taken, in accordance with Article 33(5) GDPR.
As an early-stage company, Proveit's breach response procedures are actively maintained and improved. If you discover a security vulnerability please contact info@getproveit.io immediately.
3. Reporting a vulnerability
If you discover a security vulnerability in the Proveit platform, please contact us immediately at info@getproveit.io.
We commit to acknowledging your report within 24 hours and to keeping you informed of our progress. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and address it.
4. Contact
For security-related enquiries, contact Verid at info@getproveit.io.
