Security & compliance

Enterprise-grade protections are on by default. No additional configuration is required for most features.

PII masking
Customer messages are scanned before reaching your LLM. Emails, phone numbers, SSNs, and credit card numbers are stripped in real time, helping with GDPR and HIPAA compliance.
Single sign-on (SSO)
Connect Google Workspace, Okta, Azure AD, or any OIDC provider under Settings → SSO. You can restrict admin dashboard access to specific email domains.
Security audit ledger
Every login, key change, file deletion, and settings update is logged with timestamp, operator email, IP address, and raw payload. View it under Settings → Audit Log.
AI Critic (anti-hallucination)
Before every response reaches a customer, a secondary model checks the answer against your actual knowledge base documents. Contradictions and fabricated facts are blocked automatically.
Set rate limits at the organization, session, or request level under Settings → Rate Limits to cap LLM spend and protect against abuse.

Enterprise-Grade Security Architecture

Verabase is designed with a fundamental principle: your data remains your data. We employ a zero-trust security model that ensures absolute isolation between tenant environments. All data at rest is encrypted using AES-256, and all data in transit is secured via TLS 1.3. We undergo rigorous independent SOC 2 Type II and ISO 27001 audits annually to validate our security posture.

Bring Your Own Key (BYOK)

For organizations with strict compliance requirements, our Bring Your Own Key (BYOK) feature allows you to manage and rotate the cryptographic keys used to secure your vector databases and knowledge graphs. You retain complete control—if you revoke the key, your data becomes immediately cryptographically inaccessible to our systems.

Role-Based Access Control (RBAC)

Granular Role-Based Access Control (RBAC) allows you to define exactly who can view, edit, or approve changes within your Verabase workspace. You can restrict access to specific agents, knowledge domains, or analytics dashboards, ensuring that sensitive internal documentation is only accessible to authorized personnel, while public-facing AI agents operate safely within their defined semantic boundaries.