Security & Trust
Built to be reviewed by your security team.
VerifyScience helps researchers and institutions assess the credibility of scientific work.
We hold ourselves to the same standard of transparency we apply to research: this page sets
out, in plain terms, how we protect your data, where it lives, who processes it, and what we
are still building. It is written to support institutional vendor review.
๐ฌ๐ง UK data residency
๐ Encrypted at rest & in transit
๐ GDPR compliant
๐ค EU AI Act aligned
Data protection & encryption
How information is protected in storage and in motion.
๐
Encryption at rest
Sensitive secrets, including any user-supplied API keys, are encrypted with AES-256-GCM before they are stored. Encryption keys are held separately from the data they protect.
๐
Encryption in transit
All traffic to and from VerifyScience is served over HTTPS/TLS. Authentication uses httpOnly, SameSite session cookies that are not readable by client-side scripts.
๐ฌ๐ง
UK data residency
Application data is hosted in a United Kingdom region. Personal data is handled under UK GDPR and the EU GDPR, with appropriate safeguards for any onward processing.
๐๏ธ
Database isolation
Records are stored in a managed PostgreSQL database with row-level security (RLS), so each account's data is logically isolated and access is enforced at the database layer.
Access control & authentication
Who can reach data, and how privileged actions are gated.
Sign-in via Google and Microsoft single sign-on (OAuth 2.0); we never store account passwords.
Server-side session validation on every authenticated request, with httpOnly cookies and CSRF origin checks on state-changing actions.
Privileged internal operations (background processing, administrative endpoints) are gated behind a separate internal secret and are not reachable from the public surface.
Least-privilege access: each component holds only the credentials it needs, and secrets are managed as environment configuration, not committed to source.
Application security practices
Security is built into how the product is engineered, not added afterwards.
๐ก๏ธ
Input validation & SSRF protection
User-supplied URLs and content are validated and sanitised. Server-side request controls guard against server-side request forgery when fetching external paper sources.
๐งฑ
Hardened HTTP headers
A strict Content-Security-Policy and a full set of security response headers are applied globally to reduce injection and clickjacking risk.
๐
Secure development lifecycle
Changes follow defined pre-merge security checks, dependency hygiene, and review against the OWASP Top 10 before release.
โฑ๏ธ
Abuse & rate controls
Per-user rate limiting and usage ceilings protect the platform and downstream providers from abuse and runaway usage.
Privacy & data rights
We collect the minimum needed to run the service, and you stay in control of it.
Data minimisation: we store only what is required to operate verification, billing, and account management.
Right of access: users can request a complete export of their personal data (GDPR Article 15 subject access request).
Right to erasure: account deletion cascades across verification records, watches, sessions, and related data (GDPR Article 17).
Submitted paper content is processed to produce an assessment and is not sold, and is not used to train third-party foundation models under our providers' commercial API terms.
A Data Processing Agreement (DPA) and sub-processor list are available to institutional customers on request.
Full detail is set out in our Privacy Policy.
Sub-processors
The third parties that help deliver the service, and what each one handles.
| Provider | Purpose | Data involved |
| Anthropic (Claude API) | AI analysis of submitted papers | Paper content submitted for verification |
| Supabase | Managed PostgreSQL database & auth storage | Account, verification, and billing records |
| Netlify | Application hosting & serverless functions | Request handling; no long-term data store |
| Stripe | Payment & subscription processing | Billing and payment data (PCI-handled by Stripe) |
| Resend | Transactional email delivery | Email address and notification content |
| OpenAlex & Crossref | Public citation & retraction metadata | Public identifiers only (DOI, etc.) |
An up-to-date sub-processor register is provided to institutional customers as part of vendor due diligence.
AI governance & transparency
Responsible use of AI is core to a credibility product.
Assessments are AI-generated guidance to support expert judgement, not a definitive verdict on a paper's validity.
Every result carries a clear AI-disclosure notice, in line with EU AI Act transparency expectations.
Human-in-the-loop by design: outputs are intended to inform reviewers, authors, and editors, who retain the decision.
Our assessment methodology is described openly on our
Methodology page.
Business continuity & incident response
How we keep the service running and how we respond if something goes wrong.
Managed infrastructure with provider-level redundancy and automated database backups.
A defined incident-response process covering detection, containment, and remediation.
In the event of a personal-data breach, we commit to notifying affected customers and the relevant supervisory authority without undue delay, consistent with GDPR (within 72 hours where required).
Responsible disclosure welcomed: security researchers can report issues directly to our team (see below).
Compliance posture & roadmap
An honest statement of where we are today and what we are working towards.
๐UK & EU GDPR
DPA, SAR & erasure in place
๐คEU AI Act
Transparency & disclosure aligned
๐ฌ๐งUK data residency
Hosted in UK region
On our roadmap
Independent third-party penetration testing.
SOC 2 and/or ISO 27001 readiness as we scale into larger institutional deployments.
Completed HECVAT and SIG vendor-assessment questionnaires, available to institutions on request.
A note on honesty
VerifyScience does not hold SOC 2 or ISO 27001 certification today, and we will not claim otherwise. We would rather give you an accurate picture of our security posture and our roadmap than overstate it โ the same principle that underpins the product itself.
Last updated: 28 June 2026 ยท VerifyScience ยท AVIADA Agentic AI Solutions Ltd ยท Company No. 16941983, London