GDPR
The European data-protection regulation. Lawful basis, purpose limitation, data minimisation, and the rights of the data subject — treated as a non-negotiable floor.
Veritas-Vault is engineered against six data-protection and information-security frameworks simultaneously. The memory-only architecture is what makes that simultaneity possible — there is one substrate to certify, not six adaptations.
Each framework below describes a body of obligation. Veritas-Vault meets the data-minimisation core of every one structurally — through memory-only processing, rather than through policy documents. Veritas-Vault is not certified against these frameworks. The platform is engineered to their requirements, and the architecture is open to review by any client who wishes to test it.
The European data-protection regulation. Lawful basis, purpose limitation, data minimisation, and the rights of the data subject — treated as a non-negotiable floor.
The post-Brexit successor regime. Substantively aligned with the EU framework, with ICO-specific obligations and the UK's own adequacy posture observed.
The revised Swiss federal regime, effective September 2023. The domestic standard against which a Geneva-domiciled platform is measured.
An attestation of operational controls across security, availability, processing integrity, confidentiality, and privacy — measured over a defined observation period.
The international standard for information-security management systems. Risk-based controls across people, process, and technology — assessed as one integrated programme.
The South African data-protection regime. Operative for institutional counsel with cross-border exposure into the Republic and the wider SADC region.
Architecture and security documentation available on request, under NDA.
Veritas-Vault uses Cloudflare Web Analytics to monitor aggregate site traffic. No cookies. No personal data. No third-party trackers. Visit counts and referrer paths only — held by Cloudflare under EU data-protection terms.
The list below describes what Veritas-Vault does not collect, measure, infer, or share — at any layer of the site, the platform, or the report-delivery pipeline.
A processor should be willing to say who else touches the work. The following sub-processors are engaged in the delivery of the platform. Each is bound by a data processing agreement, and Standard Contractual Clauses are in place where an international transfer is in scope.
| Sub-processor | Purpose | What it receives |
|---|---|---|
| Anthropic PBC | Inference — the analysis itself | The document text, for the duration of the analysis |
| Vercel Inc. | Application hosting and serverless execution | Request traffic in transit; no document is written to storage |
| Supabase | Authentication and billing records (EU region) | Account email and page counts. No document. No findings. |
| Stripe | Payment processing | Billing details only |
| Cloudflare | Aggregate web analytics; DNS | Visit counts and referrer paths. No cookies, no personal data. |
| Resend | Transactional email (account and password messages) | Account email address only |
The analysis is performed by Anthropic models called through the Claude API. The document is transmitted for the duration of the analysis and is not used to train any model. Under Anthropic’s published API terms, conversation content is not retained by default, and Veritas-Vault engages none of the features that would require retention — no file storage, no batch processing, no code execution.
One exception is disclosed for completeness, because a processor that hides its carve-outs is not worth trusting: where a request is flagged by Anthropic’s automated abuse-detection systems, inputs and outputs may be retained by Anthropic for up to two years. This applies to every customer of that API and is outside our control. It is disclosed in the Data Processing Agreement.
Beyond that single exception, no sub-processor holds your document after the report is delivered, and Veritas-Vault itself holds no copy at any point — the memory-only architecture makes retention structurally impossible rather than merely prohibited.
A standard Data Processing Agreement is available for institutional clients whose engagement requires Veritas-Vault to act as data processor under Article 28 GDPR (and equivalent provisions under UK GDPR, Swiss FADP, and POPIA). The agreement covers sub-processing, international transfers, breach notification, and deletion on termination — though the latter is, in practice, structurally guaranteed by the memory-only architecture itself.
Standard Contractual Clauses are appended where international transfer is in scope. A redlined draft is shared at the scoping stage of any engagement.