Your data, your decisions.
Decisions are deterministic. Explanations are opt-in. The data path stays under our roof.
- No LLM in the decision path
- Operated on infrastructure we own
- Encryption in transit and at rest
Three things to know before procurement opens a ticket.
The decision path is deterministic. LLMs only render explanations when you opt in.
Core enrichment runs on infrastructure we operate. We don't pass customer queries to third-party processors.
Privacy controls, customer rights, and processor obligations met under the GDPR framework.
LLM-free by default
The first vendor-review question today is "do you send our queries to OpenAI or Anthropic?" The answer for VerdictIQ is no, not unless you ask us to.
Verdict, signals, evidence, and risk score are produced by rule-based aggregation and a signal pipeline. No LLM is involved on this path. Submit the same IOC twice and the verdict is identical. No randomness, no hallucination.
If you want a human-readable narrative of the result, open the verdict in the VerdictIQ portal and run Enrich with VerdictIQ AI from the menu. An LLM layer reads the existing verdict and signal metadata and produces text. It does not produce or change the verdict.
If you don't enable explanation, your query never reaches an LLM provider. This is the default behavior on every plan, including Free.
- The verdict (malicious / clean / suspicious)
- The signals that fired (e.g. dga, phishing, cdn)
- Public metadata such as registration age and popularity tier
- Nothing else
- Raw customer telemetry
- User identifiers beyond your API key
- Internal log lines or free-text fields
- Any data not strictly needed to render the explanation
When the explanation layer is enabled, we use an industry-standard LLM provider under a no-training agreement. Customer-derived inputs are not used for model training and are not retained beyond the provider's no-retention window. The provider name is available under NDA.
Every LLM invocation is logged on our side with request ID, timestamp, and inputs sent. Customers may request their LLM-call audit trail in writing.
Own infrastructure, no third-party data sharing
VerdictIQ runs on infrastructure we own and operate, including the website, API, and signal pipeline. The product is not built on top of a third-party threat intelligence vendor.
We do not share customer queries or query results with third-party processors for the core enrichment service.
Marketing analytics on the website is collected at minimum and listed in our privacy policy. The enrichment data path and the marketing data path are kept separate.
Vendor due-diligence usually requires a sub-processor list. Ours is intentionally minimal. There is no upstream CTI vendor to audit; the chain stops with us.
Compliance
We act as data processor for customer-submitted IOCs and as data controller for the marketing site. Standard contractual clauses are available in our DPA. Data subject rights (access, deletion, portability) are honored via privacy@verdictiq.io.
Customers across the EEA are supported under standard contractual clauses where applicable, with response windows aligned to GDPR statutory periods.
Our security and privacy controls are designed in line with widely accepted industry practice (encryption, least-privilege access, audit logging, secrets management). We do not currently claim SOC 2 or ISO 27001 certification.
We will not list a certification on this page that we have not earned. The absence of a badge means we have not been audited yet, not that the controls are missing.
Data handling
What we receive, what we store, what we don't.
| Question | Answer |
|---|---|
| What do you receive from customers? | IOCs (domain, URL, IP, hash) submitted to the enrichment API. |
| What do you store? | The IOC, the verdict, signal metadata, and request timestamps. Aggregated analytics for billing and abuse detection. |
| What do you NOT store? | Free-text inputs, user identifiers beyond the API key, customer telemetry, internal log lines. |
| Retention | Active query logs are kept for a short rolling window for operational and abuse-detection purposes; the exact term is agreed per contract. Aggregated, de-identified metrics may persist longer, with no IOC-level detail. |
| Deletion | Customers may request deletion of their submitted IOC log via privacy@verdictiq.io. Aggregated, de-identified metrics may persist. |
| Encryption | TLS 1.2+ in transit. Encryption at rest for all customer-submitted data. |
| Customer access to their data | Manual export available via support today. A self-serve audit endpoint is planned. |
Security controls
TLS 1.2+ for all transport. Encryption at rest with managed keys.
Least-privilege IAM. Customer data access restricted to a small on-call group; access events are logged and reviewed.
Mandatory on all internal admin surfaces.
Production access, deployment events, and customer-data reads are logged centrally with tamper-evident retention.
Centralized secret store. No plaintext credentials in code, build artifacts, or container images.
Dependencies are scanned on build. Critical patches are applied within an internal SLA tracked in our changelog.
Periodic encrypted backups with documented restore procedure.
Privacy rights
For customers and data subjects, the following rights are honored under GDPR.
- Access: request a copy of personal data we hold about you.
- Rectification: correct inaccurate data.
- Erasure: request deletion, subject to lawful retention obligations.
- Portability: receive your data in a machine-readable format.
- Objection or restriction: object to specific processing.
- Withdraw consent: where processing relies on consent.
Submit requests to privacy@verdictiq.io. We respond within the GDPR statutory window (30 days).
- Privacy Policy
- Data Processing Agreement (DPA, draft, available on request)
- Terms of Service
Vulnerability disclosure
security@verdictiq.io. PGP key available on request.
Reproducible steps, the affected endpoint, and suspected impact. Do not include real customer data in the report.
- Acknowledgement within 2 business days.
- Triage update within 7 business days.
- Remediation timeline communicated based on severity.
Good-faith research that does not exfiltrate customer data, degrade service, or violate privacy will not be pursued legally. We credit reporters in the changelog when they consent.
Denial-of-service tests, social engineering of staff, physical attacks.
Talk to our security team.
Vendor review questionnaire, DPA negotiation, custom retention terms; we work with procurement directly.