Security
Last updated · June 18, 2026
Verity is intended for workflows that may involve sensitive care information, so security is foundational, not an afterthought. This page summarizes the controls we are designing and validating for a controlled pilot; it is not a certification or compliance claim. Prospective pilot partners can ask which evidence is currently available for review.
Our approach
We design for the sensitivity of care data: collect the minimum, restrict access tightly, log everything, and keep a human accountable for what becomes official.
Data residency
Verity is designed to store and process customer data in Canadian regions. We do not intend to move care records outside the country without explicit agreement.
Encryption
Verity is designed to encrypt data in transit (TLS) and at rest using industry-standard algorithms. Keys are designed to be managed through a dedicated key-management service with rotation.
Access control
Access is designed to follow least-privilege principles, gated by role and multi-factor authentication. Production access is designed to be restricted, time-bound, and logged.
Review & audit
Verity is designed so that every record passes through human review before it's official, and every action leaves an audit trail — who saw what, who changed what, and when.
Compliance
We are preparing PHIPA and PIPEDA alignment analysis, and SOC 2 readiness remains to be validated. Before any pilot involving customer data, we would document and validate roles, safeguards, subprocessors, retention, and contractual terms with the customer and appropriate advisers.
Report an issue
Found a vulnerability? We appreciate responsible disclosure. Email security@tryverity.ca and we'll respond promptly.