Skip to content
TRUST & SECURITY

Your data, your decisions.

Decisions are deterministic. Explanations are opt-in. The data path stays under our roof.

  • No LLM in the decision path
  • Operated on infrastructure we own
  • Encryption in transit and at rest
Talk to securityEmail security

LLM-free by default

The first vendor-review question today is "do you send our queries to OpenAI or Anthropic?" The answer for VerdictIQ is no, not unless you ask us to.

Decision path is deterministic.

Verdict, signals, evidence, and risk score are produced by rule-based aggregation and a signal pipeline. No LLM is involved on this path. Submit the same IOC twice and the verdict is identical. No randomness, no hallucination.

Explanation is opt-in.

If you want a human-readable narrative of the result, open the verdict in the VerdictIQ portal and run Enrich with VerdictIQ AI from the menu. An LLM layer reads the existing verdict and signal metadata and produces text. It does not produce or change the verdict.

Default: zero LLM calls.

If you don't enable explanation, your query never reaches an LLM provider. This is the default behavior on every plan, including Free.

When explanation is on, here is what we send:

  • The verdict (malicious / clean / suspicious)
  • The signals that fired (e.g. dga, phishing, cdn)
  • Public metadata such as registration age and popularity tier
  • Nothing else
What is never sent:

  • Raw customer telemetry
  • User identifiers beyond your API key
  • Internal log lines or free-text fields
  • Any data not strictly needed to render the explanation
Provider arrangement

When the explanation layer is enabled, we use an industry-standard LLM provider under a no-training agreement. Customer-derived inputs are not used for model training and are not retained beyond the provider's no-retention window. The provider name is available under NDA.

Audit

Every LLM invocation is logged on our side with request ID, timestamp, and inputs sent. Customers may request their LLM-call audit trail in writing.

Own infrastructure, no third-party data sharing

VerdictIQ runs on infrastructure we own and operate, including the website, API, and signal pipeline. The product is not built on top of a third-party threat intelligence vendor.

We do not share customer queries or query results with third-party processors for the core enrichment service.

Marketing analytics on the website is collected at minimum and listed in our privacy policy. The enrichment data path and the marketing data path are kept separate.

Why this matters for procurement

Vendor due-diligence usually requires a sub-processor list. Ours is intentionally minimal. There is no upstream CTI vendor to audit; the chain stops with us.

Compliance

GDPR (EU)

We act as data processor for customer-submitted IOCs and as data controller for the marketing site. Standard contractual clauses are available in our DPA. Data subject rights (access, deletion, portability) are honored via privacy@verdictiq.io.

EEA reach

Customers across the EEA are supported under standard contractual clauses where applicable, with response windows aligned to GDPR statutory periods.

Industry standards

Our security and privacy controls are designed in line with widely accepted industry practice (encryption, least-privilege access, audit logging, secrets management). We do not currently claim SOC 2 or ISO 27001 certification.

Honest disclosure

We will not list a certification on this page that we have not earned. The absence of a badge means we have not been audited yet, not that the controls are missing.

Data handling

What we receive, what we store, what we don't.

QuestionAnswer
What do you receive from customers?IOCs (domain, URL, IP, hash) submitted to the enrichment API.
What do you store?The IOC, the verdict, signal metadata, and request timestamps. Aggregated analytics for billing and abuse detection.
What do you NOT store?Free-text inputs, user identifiers beyond the API key, customer telemetry, internal log lines.
RetentionActive query logs are kept for a short rolling window for operational and abuse-detection purposes; the exact term is agreed per contract. Aggregated, de-identified metrics may persist longer, with no IOC-level detail.
DeletionCustomers may request deletion of their submitted IOC log via privacy@verdictiq.io. Aggregated, de-identified metrics may persist.
EncryptionTLS 1.2+ in transit. Encryption at rest for all customer-submitted data.
Customer access to their dataManual export available via support today. A self-serve audit endpoint is planned.

Security controls

Encryption

TLS 1.2+ for all transport. Encryption at rest with managed keys.

Access control

Least-privilege IAM. Customer data access restricted to a small on-call group; access events are logged and reviewed.

MFA

Mandatory on all internal admin surfaces.

Audit logging

Production access, deployment events, and customer-data reads are logged centrally with tamper-evident retention.

Secrets management

Centralized secret store. No plaintext credentials in code, build artifacts, or container images.

Vulnerability management

Dependencies are scanned on build. Critical patches are applied within an internal SLA tracked in our changelog.

Backup and recovery

Periodic encrypted backups with documented restore procedure.

Privacy rights

For customers and data subjects, the following rights are honored under GDPR.

  • Access: request a copy of personal data we hold about you.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion, subject to lawful retention obligations.
  • Portability: receive your data in a machine-readable format.
  • Objection or restriction: object to specific processing.
  • Withdraw consent: where processing relies on consent.

Submit requests to privacy@verdictiq.io. We respond within the GDPR statutory window (30 days).

Documents

Vulnerability disclosure

Contact

security@verdictiq.io. PGP key available on request.

What to send

Reproducible steps, the affected endpoint, and suspected impact. Do not include real customer data in the report.

What we commit to

  • Acknowledgement within 2 business days.
  • Triage update within 7 business days.
  • Remediation timeline communicated based on severity.
Safe harbor

Good-faith research that does not exfiltrate customer data, degrade service, or violate privacy will not be pursued legally. We credit reporters in the changelog when they consent.

Out of scope

Denial-of-service tests, social engineering of staff, physical attacks.

Talk to our security team.

Vendor review questionnaire, DPA negotiation, custom retention terms; we work with procurement directly.