Security assurance

Verlox security assurance is published from one shared programme.

This is the public starting point for Verlox security assurance. It points to the controls, operating guidance, and reporting paths that customers ask for before they buy. Only approved, current answers should be published, and anything product-specific must be checked against the live deployment before it is stated publicly.

01

Current posture

Verlox publishes only approved claims. Anything product-specific must match the current deployment and the shared assurance record.

02

What to ask for

Encryption, access control, logging, recovery, incident response, and vulnerability reporting are all covered in the assurance programme.

03

What is not published here

Unreviewed certifications, dates, regions, retention periods, pen test results, or any claim that is not backed by the current assurance record.

Assurance

How we answer security questionnaires

Answers are maintained in the shared assurance programme, checked against the current deployment, and only published when they match product reality. If the question combines multiple controls, each part should be answered separately and qualified where needed.

  • Use current, product-specific facts only
  • Do not turn planned work into current capability
  • Do not publish stronger wording than the evidence supports
Report a vulnerability

Public claims are controlled. Security review is required before publication.