Resources · Security & Trust

Built for the world's most
sensitive workloads.

Security is a property of the platform, not a feature bolted on. Data sovereignty, zero-trust access, AI guardrails and audit are enforced on every request, wherever you deploy.

Trust pillars

Six commitments,
enforced by design.

Data Sovereignty

Your data stays where your mandate requires: on-prem, in your private or national cloud, or fully air-gapped.

Zero-Trust Access

Every request is authenticated and authorized: SSO, MFA and least-privilege roles.

Encryption Everywhere

Encrypted in transit and at rest, with managed secrets and key rotation.

AI Guardrails

Prompt-injection screening, PII redaction and clearance checks run on every AI request, in and out.

Tenant Isolation

Isolated tenants with independent policies, quotas and data: row-level security and attribute-based access.

Audit

An audit ledger and traces record every significant event. Provable, not just logged.

Defense in depth

Security at every layer.

Controls are layered from the perimeter to the audit ledger. A failure at any single layer is contained by the next.

Perimeter

API Gatewayversioned · rate-limited
Ingress GuardsSSRF · input · size

Identity & access

SSO & MFAOIDC · SAML
RBAC / ABACleast privilege
Tenant IsolationRLS

Data protection

Encryptiontransit & rest
Secrets & Keysmanaged · rotated
Retention & Purgedata lifecycle

AI guardrails

Policy Engineinput & output guardrails: prompt-injection · PII redaction · clearance

Assurance

Auditaudit log
Monitoringmetrics · alerts
Backup & DRrestore paths

AI security

Governed AI, by default.

No application ever calls a model directly. Every AI request passes through the governed control plane, where policy is enforced before and after inference.

No Direct Model Calls

Applications call the AI Service Bus, never a model. Routing, policy and audit can never be bypassed.

Prompt-Injection Screening

Inputs are screened for injection and manipulation before they reach a model.

PII Detection & Redaction

Sensitive data is detected and masked before the model sees it, and checked again on output.

Sensitivity Routing

Classified or sensitive workloads route only to permitted models, on-prem or air-gapped when required.

Human-in-the-Loop

Approval gates hold high-impact actions for a person to review before they execute.

Full Traceability

Every decision ties back to its inputs, policy and model on an audit trace.

Compliance & frameworks

Designed to support
your obligations.

The platform is built to help you meet recognized governance and security frameworks. Framework alignment supports your compliance program. It does not replace your own assessment.

ISO 27001SOC 2GDPRPDPLNDMONCARDGAData residencyGovernment compliance reporting

Certifications & attestations

Formal certifications and third-party attestations are placeholders, provided on request and added here as completed. We do not claim certifications we do not hold.

Controls

The controls your
security team expects.

SSO: OIDC & SAML 2.0 Provisioning: SCIM & directory sync Access: RBAC, ABAC, per-capability Encryption: in transit & at rest Secrets: managed & rotated Isolation: multi-tenant, row-level security Audit: audit log Resilience: backups, retention, DR

Sovereignty

Run it where your
data must live.

From public cloud to fully disconnected, on-host deployments: your models, your data, your jurisdiction.

CloudPrivate CloudGovernment CloudNational CloudHybridOn-PremisesAir-Gapped
Responsible disclosure

Report a vulnerability

If you believe you've found a security issue, we want to hear from you. Email our security team at security@veevra.com with details and steps to reproduce, and we'll respond promptly.

For your review

Security documentation

We share our security overview, architecture and deployment details with prospective and existing customers under NDA. Request a copy and we'll set up a session with our security team.

Evaluating VEEVRA for a
regulated workload?

We'll walk your security and compliance teams through the model, controls and deployment options in detail.