How your data is protected

For the person at your company who asks "is this safe?". Written so it can be forwarded as it is. Version of October 4, 2026. The companion page, what we read and what we cannot do, covers scope; this one covers security.

1. Each customer has their own database

Your account is a separate database file on the server, with its own folder for credentials, uploaded files and exports. No table is shared between customers. A question about your fleet can only ever be answered from your own data, and there is no report that combines customers, because the manufacturers' terms forbid it and so do we.

2. Credentials are encrypted and never shown again

A manufacturer key or token you give us is encrypted at rest with a key that lives only in the server's configuration, not in the code and not in any backup of the database. Once saved it is never displayed, not to you and not to us. Changing it means pasting a new one. For brands that connect with a sign-in and an Allow button, we never see your password at all; the manufacturer hands us a token that you can revoke on their site.

3. Access is read-only

We ask each manufacturer for the narrowest view-only permission they offer. Our software has no code path that writes to a machine or to your manufacturer account. The only thing we ever write anywhere outside our own system is the accounting file or journal entry you approve by hand, and only to the place you point it at.

4. Every data access by the software is logged

The four questions we answer are plain arithmetic programs. Each one reads through a small set of tools, and every call they make is written to a log you can inspect: which tool, which machine, when. The optional writing assistant that words a recommendation can only use numbers that already appear in the evidence; anything else is rejected before it reaches your page. It has no tool that can send an email, change a record, or act for you.

4b. Accounting connections

When you connect QuickBooks Online or Xero, we store the connection token encrypted, read bills, vendors and your own labels, and write only the journal entries you approve and, if you switch it on, the machine's label on a bill. Nothing from your books is passed to anyone else. The option to send an attached invoice to the writing assistant for reading is off until you turn it on, and applies only to bills we could not place. Disconnecting in Verrum or in your accounting system revokes the token at once. Pages and data answers are sent with no-store caching, over HTTPS only.

5. Who can log in

You and the people you add. Each person gets their own code, shown once; removing a person signs them out at once. Changing the account code signs everyone else out. The site runs only over an encrypted connection and never without a password.

6. Where it runs, and backups

On a hosting service in the United States, on a persistent disk. The database is backed up as a complete copy that can be restored in minutes. Backups are deleted within 30 days after an account is deleted.

7. Switching us off

You can do it yourself, without asking: remove the connection under "Connect brands" in your account, or revoke us at the manufacturer. Our access stops the moment you do. Deleting the account and everything in it is one email away and done within 7 days.

8. What we do not yet have, said plainly

9. Reporting a problem

If you believe something is wrong, write to the address below. You will get a reply from the person who runs the software, not a form.

Abimanyu
Founder, Verrum
abimanyu@verrumfleet.com

Related pages: the data agreement, privacy, terms of use.