Security & compliance

Built for the buyer
whose auditor asks.

Vered runs regulated manufacturers, so security is not a page — it is how the product is built. Every claim below is enforced in code and points at where. Not asserted — provable.


01/Isolation

Your data cannot reach another tenant

Isolation is enforced at the database on every write — not left to application code to remember. We verify it, and a standing check fails the build if a new write could ever bypass it.

One tenant can never read or write another's data — isolation is enforced at the database on every write, not just in application coderow-level security on writes + the guard:write-authz check that blocks any admin write keyed on an id without an org scope

02/Access control

Least privilege, proven role by role

Not a claim on a slide — we log in as each role and confirm it reaches exactly its granted modules and nothing else.

Every role sees exactly the modules it is granted and nothing more — verified role by role, with no privilege-escalation path5 roles tested, zero privilege escalation
Set permissions per role and override per userrole templates + per-user overrides
License modules per organisation — buy one, add more later, with the product genuinely enforcing itmodule licensing is the outer ceiling
Multi-factor authentication is enforced on regulated workflows, backed by a complete, tamper-evident audit trailMFA on regulated paths + append-only audit trail

03/AI guardrails

The AI is barred from what it must never do

For a regulated buyer this is the question that matters, and the answer is a mechanism, not a promise: the prohibitions are enforced when the code loads.

AI is barred in code from the actions it must never take — it cannot post a journal entry, alter a Part 11 record, move a pipeline stage, or send an external messagethe action registry’s no-list throws at module load — if someone tries to register a forbidden action, the product does not start
Asked live: post $40,000 straight into the general ledger. Bromel refuses and says why — it cannot post journal entries or GL transactions. The no-list is enforced when the code loads, not asked of the model.Recorded live, demo data

04/Your data

Yours to inspect, yours to leave with

Export your datafull export, on demand
See exactly what AI cost you, by org and by dayAI spend visible per org, per day

In practice

Bring your security team. We’ll show you the controls.

Everything on this page is enforced in code and points at where. For a questionnaire or a diligence request, we’ll walk your team through each control in detail — and hand them the evidence.

SOC 2 Type II is underway; the controls it attests to are in place today.