Security & Trust

Built to be reviewed by your security team.

VerifyScience helps researchers and institutions assess the credibility of scientific work. We hold ourselves to the same standard of transparency we apply to research: this page sets out, in plain terms, how we protect your data, where it lives, who processes it, and what we are still building. It is written to support institutional vendor review.

๐Ÿ‡ฌ๐Ÿ‡ง UK data residency ๐Ÿ”’ Encrypted at rest & in transit ๐Ÿ“œ GDPR compliant ๐Ÿค– EU AI Act aligned

Data protection & encryption

How information is protected in storage and in motion.

๐Ÿ”
Encryption at rest
Sensitive secrets, including any user-supplied API keys, are encrypted with AES-256-GCM before they are stored. Encryption keys are held separately from the data they protect.
๐Ÿ”—
Encryption in transit
All traffic to and from VerifyScience is served over HTTPS/TLS. Authentication uses httpOnly, SameSite session cookies that are not readable by client-side scripts.
๐Ÿ‡ฌ๐Ÿ‡ง
UK data residency
Application data is hosted in a United Kingdom region. Personal data is handled under UK GDPR and the EU GDPR, with appropriate safeguards for any onward processing.
๐Ÿ—„๏ธ
Database isolation
Records are stored in a managed PostgreSQL database with row-level security (RLS), so each account's data is logically isolated and access is enforced at the database layer.

Access control & authentication

Who can reach data, and how privileged actions are gated.

Sign-in via Google and Microsoft single sign-on (OAuth 2.0); we never store account passwords.
Server-side session validation on every authenticated request, with httpOnly cookies and CSRF origin checks on state-changing actions.
Privileged internal operations (background processing, administrative endpoints) are gated behind a separate internal secret and are not reachable from the public surface.
Least-privilege access: each component holds only the credentials it needs, and secrets are managed as environment configuration, not committed to source.

Application security practices

Security is built into how the product is engineered, not added afterwards.

๐Ÿ›ก๏ธ
Input validation & SSRF protection
User-supplied URLs and content are validated and sanitised. Server-side request controls guard against server-side request forgery when fetching external paper sources.
๐Ÿงฑ
Hardened HTTP headers
A strict Content-Security-Policy and a full set of security response headers are applied globally to reduce injection and clickjacking risk.
๐Ÿ”
Secure development lifecycle
Changes follow defined pre-merge security checks, dependency hygiene, and review against the OWASP Top 10 before release.
โฑ๏ธ
Abuse & rate controls
Per-user rate limiting and usage ceilings protect the platform and downstream providers from abuse and runaway usage.

Privacy & data rights

We collect the minimum needed to run the service, and you stay in control of it.

Data minimisation: we store only what is required to operate verification, billing, and account management.
Right of access: users can request a complete export of their personal data (GDPR Article 15 subject access request).
Right to erasure: account deletion cascades across verification records, watches, sessions, and related data (GDPR Article 17).
Submitted paper content is processed to produce an assessment and is not sold, and is not used to train third-party foundation models under our providers' commercial API terms.
A Data Processing Agreement (DPA) and sub-processor list are available to institutional customers on request.

Full detail is set out in our Privacy Policy.

Sub-processors

The third parties that help deliver the service, and what each one handles.

ProviderPurposeData involved
Anthropic (Claude API)AI analysis of submitted papersPaper content submitted for verification
SupabaseManaged PostgreSQL database & auth storageAccount, verification, and billing records
NetlifyApplication hosting & serverless functionsRequest handling; no long-term data store
StripePayment & subscription processingBilling and payment data (PCI-handled by Stripe)
ResendTransactional email deliveryEmail address and notification content
OpenAlex & CrossrefPublic citation & retraction metadataPublic identifiers only (DOI, etc.)

An up-to-date sub-processor register is provided to institutional customers as part of vendor due diligence.

AI governance & transparency

Responsible use of AI is core to a credibility product.

Assessments are AI-generated guidance to support expert judgement, not a definitive verdict on a paper's validity.
Every result carries a clear AI-disclosure notice, in line with EU AI Act transparency expectations.
Human-in-the-loop by design: outputs are intended to inform reviewers, authors, and editors, who retain the decision.
Our assessment methodology is described openly on our Methodology page.

Business continuity & incident response

How we keep the service running and how we respond if something goes wrong.

Managed infrastructure with provider-level redundancy and automated database backups.
A defined incident-response process covering detection, containment, and remediation.
In the event of a personal-data breach, we commit to notifying affected customers and the relevant supervisory authority without undue delay, consistent with GDPR (within 72 hours where required).
Responsible disclosure welcomed: security researchers can report issues directly to our team (see below).

Compliance posture & roadmap

An honest statement of where we are today and what we are working towards.

๐Ÿ“œ
UK & EU GDPR
DPA, SAR & erasure in place
๐Ÿค–
EU AI Act
Transparency & disclosure aligned
๐Ÿ‡ฌ๐Ÿ‡ง
UK data residency
Hosted in UK region

On our roadmap

Independent third-party penetration testing.
SOC 2 and/or ISO 27001 readiness as we scale into larger institutional deployments.
Completed HECVAT and SIG vendor-assessment questionnaires, available to institutions on request.
A note on honesty
VerifyScience does not hold SOC 2 or ISO 27001 certification today, and we will not claim otherwise. We would rather give you an accurate picture of our security posture and our roadmap than overstate it โ€” the same principle that underpins the product itself.
Security & vendor due diligence

Conducting a vendor security review, or need to report a vulnerability? Write to hello@verifyscience.co.uk and we will respond promptly. Institutional evaluators can request our security documentation pack, Data Processing Agreement, and sub-processor register, and we are happy to complete your vendor assessment questionnaire (HECVAT, SIG, or your own).

Last updated: 28 June 2026 ยท VerifyScience ยท AVIADA Agentic AI Solutions Ltd ยท Company No. 16941983, London