Sovereignty and trust

Your evidence never leaves your building.

This page is written for the person who has to sign off on the risk rather than for the person who wants the software. Everything a security review normally asks is answered below, and anything that is not answered is a question worth sending to me directly.

  • No internet connection required or used
  • No telemetry, no vendor remote access
  • Models run on your hardware and can be replaced

The architecture, in one paragraph

A closed deployment inside your perimeter.

VERA is installed as a client on analyst workstations, with a central inference server on your own intranet. The two speak to each other and to nothing else. Evidence is read from your own storage, read only, and the software has no configuration in which investigation data crosses your network boundary.

There is no cloud tier, no optional cloud tier, and no feature that becomes available if you connect it to the internet. A cloud-model configuration exists for organisations that have no sovereignty constraint and want a lower cost, and it is a deliberate choice made at deployment rather than a default.

The best way to test this is to unplug the network cable during the demonstration and carry on working. It is the first thing we suggest.

Data flows

What leaves, what stays, and what is not there at all.

Never leaves your network

  • Extractions and every record derived from them.
  • Case, seal and device identifiers.
  • Search queries and assistant conversations.
  • Audit logs and user activity.
  • Mappings, unless you choose to contribute them to a library you host.

Stays on the analyst workstation

  • Raw evidence access, which is read only at every stage.
  • The evidence store itself, which the inference server never reads.
  • Local case state and the examiner's working context.

Does not exist in the product

  • Telemetry, analytics or usage reporting of any kind.
  • An online licence check or activation call.
  • Vendor remote access, remote support tunnels or backdoors.
  • Automatic updates fetched from the internet.
  • Third-party trackers, advertising or crash reporting services.

Security review

The questionnaire, answered before you send it.

These are the questions that arrive in every security review. Answering them here saves a round trip, and it lets you judge the answers without a sales conversation attached.

Question Answer
Does the software require internet access? No. It is designed for a closed network and is deployed that way. Nothing degrades without a connection because nothing uses one.
Does the vendor have remote access? No. There is no remote support tunnel, no maintenance access and no mechanism by which I could reach a deployment.
Is there telemetry or usage reporting? No. The software collects no usage data and transmits none.
Where is investigation data processed? On your infrastructure. Raw evidence stays on the analyst workstation; only prepared text and prepared media reach your own inference server.
Is evidence access read only? Yes, at every stage of the pipeline. The evidence store is never opened with write access.
What is logged, and where does the log live? Every assistant action and every result is written to an audit log, held inside your deployment and readable by you.
Which AI models are used, and who controls them? The models run on your hardware and can be replaced by you. The client calls an internal interface, so a model change does not require a client change.
Can data reach a third-party AI provider? Not in the on-premise configuration, which is the default. A cloud-model configuration exists for organisations without sovereignty constraints and is chosen explicitly at deployment.
How are updates delivered? As packages you receive and install on your own schedule. Nothing updates itself over a network connection.
Who at the vendor can see our data? Nobody. I have no access to any deployment and no copy of any customer's data.
What happens to data if the contract ends? Nothing moves, because nothing was ever held outside your infrastructure. You remove the software and your data stays where it always was.
Is there a data processing agreement to sign? You remain the sole controller and processor of the investigation data. Where your procedure requires an agreement regardless, I will sign the one your service uses.
Can we run our own penetration test? Yes. Test the deployment in your environment under whatever conditions your policy requires, and send me the findings.
What about supply chain and dependencies? A dependency inventory for the deployed version is provided on request under the confidentiality frame described below.

If your review asks something not covered here, write to alexandre@veraforensics.com and the answer will be added to this page.

Data protection

GDPR, in the position that actually applies.

The usual complexity in a procurement file comes from a vendor processing personal data on behalf of a public authority. That situation does not arise here, because no investigation data ever reaches me or any third party.

  • You remain the controller

    Your service determines the purposes and means of processing, as it already does for the evidence itself. Nothing about that changes when VERA is installed.

  • No transfer, so no transfer mechanism

    There is no export of personal data to a processor, to a third country, or to a subprocessor, so the transfer questions in a standard file have no subject.

  • Retention is yours to set

    Data lives in your storage under your retention rules. The software imposes no retention of its own and holds no copy anywhere else.

Accessibility

EN 301 549, answered specifically rather than with a badge.

Accessibility is a procurement requirement in European public purchasing, and a blanket conformance claim from a small vendor is worth very little. So here is the precise position. This website is built to WCAG 2.1 AA: semantic structure, keyboard operation throughout, visible focus, contrast checked against the palette, and every animation reduced to its end state when the visitor has asked for reduced motion.

For the product interface, tell me which criteria your tender applies and I will answer them one at a time, including the ones where the current answer is not yet what you need. That is more useful to an evaluator than a badge, and it is the only claim I can make and keep.

Deployment

What installing it actually involves.

A closed-network deployment removes most of the steps a normal software rollout requires. There is no account provisioning, no identity federation with an external service and no network exception to negotiate.

  1. 01

    Scoping

    We agree what hardware the inference server will run on and how many analyst workstations are involved. That conversation is short, and it is the point at which the shape of the licence is settled.

  2. 02

    Installation on your hardware

    The server is installed inside your network by your team, with me available for the session. Model weights arrive with the package, so no outbound access is required at any point.

  3. 03

    Your own security testing

    Run whatever your policy requires before the software touches a real seal. I would rather you find something than not look.

  4. 04

    A first real seal

    The first case run through the deployment is the real test of coverage, and it is where the shared library starts paying for itself.

  5. 05

    Handover and documentation

    The deployment is documented so that it runs without me. That is not a courtesy, it is the answer to the continuity question a service is right to ask a single-person vendor.

Commercial model

How the licence is structured.

Figures depend on the shape of a deployment and are given on request. The structure is not confidential, and publishing it costs nothing while answering the first question procurement asks.

  • Annual licence per organisation

    Not per seat. The deployment is centralised, so charging per analyst would price a shared server as though it were a set of desktops.

  • Pilot arrangements

    A pilot small enough that procurement is not the difficult part is usually the right first step, and below the direct-award threshold no formal procedure is required.

  • Source escrow

    Escrow and a perpetual licence on the deployed version can both go into the contract. Continuity is a fair concern and it has a contractual answer.

  • No upstream licence

    VERA does not require you to hold a licence for any acquisition suite. There is no second vendor in the cost of running it.

Documents

The security brief and the capability statement.

A written security brief and a two-page capability statement are available for internal circulation inside your service. Both are issued per recipient, carry a confidentiality marking, and are sent through a private link rather than as an attachment.

Ask for them by writing to me, or request a demonstration and they will come with the follow-up.

Request the security brief

Test the sovereignty claim yourself.

Ask for the network cable to be unplugged during the demonstration and watch what keeps running. It takes ten seconds and it settles the argument better than any document.

Every request is reviewed before access is granted.