The documents your
security team asks for.
What we collect, who processes it, how long we keep it, what reaches a model, and how to report a problem. Answered here once, in public, instead of forty times in questionnaires.
Notices
Each one states what is true of the product today, and points at the control that makes it true.
These documents are in drafting and under legal review. Until they are approved they are not published here, because a legal notice nobody has reviewed is worse than none. In the meantime, Security & compliance describes the controls in force, and legal@vered.io reaches us for a diligence request, a DPA, or a security questionnaire.
No refund policy, on purpose
Vered is not sold self-serve. There is no price list, no card on file, and no way to buy the platform without a signed agreement — so cancellation, refunds, and term are negotiated in that agreement rather than declared unilaterally on a web page.
A published consumer-style refund policy would create terms that contradict the ones you actually signed. Where the two disagree, your agreement governs, and we would rather not manufacture the disagreement.
Policies say what we do. The security page shows where it is enforced.
Tenant isolation at the database, least privilege proven role by role, AI guardrails that stop the product from starting if someone registers a forbidden action, and an append-only audit trail. Every claim points at the code.