Security & Compliance
Security, privacy and responsible AI are part of the platform design.
Veriscore uses recognised regulatory and assurance frameworks as reference points for governance, technical safeguards and continuous improvement. The descriptions below distinguish legal obligations, alignment work and independent certification.
GDPR & data protection
Veriscore is designed around data minimisation, controlled access, security safeguards and support for data-subject rights. GDPR compliance ultimately depends on both technical controls and the organisation operating them correctly.
Cookies & ePrivacy
Cookie and browser-storage choices are presented separately from essential platform functions. Non-essential technologies should only be activated when the applicable consent requirements have been met.
SOC 2
Veriscore uses the SOC 2 Trust Services Criteria as a reference for security, availability, confidentiality, processing integrity and privacy controls. Veriscore does not claim to hold a SOC 2 report unless an independent examination has actually been completed.
NIS2
Risk management, incident handling, resilience, supplier security and access controls are developed with NIS2-style cybersecurity expectations in mind. Whether the legislation formally applies depends on the operating entity, service and legal scope.
ISO/IEC 27001
Information-security practices are being structured around risk-based management and controls associated with ISO/IEC 27001. Alignment is not the same as certification; certification requires an audit by an appropriate independent certification body.
EU AI Act
AI-supported features are treated according to their purpose and potential impact. Veriscore works toward transparency, human oversight, documentation and risk controls appropriate to AI used in recruitment and professional assessment contexts.
What our framework statements mean
Legal compliance, framework alignment, audit readiness and certification are different things. We use precise wording so customers are not given the impression that an external certification or assurance report exists when it does not.
Official framework and certification logos are not used as decorative trust badges. Where independent certification or assurance is obtained in the future, any mark will be used only under the rules of the organisation that issued it.
Shared controls, not separate security silos
Many good controls support several obligations at once. Strong identity and access management, for example, supports privacy, cybersecurity and assurance requirements simultaneously. Veriscore therefore maintains a common control-oriented approach rather than unrelated compliance projects.
- Access control and least-privilege principles
- Encryption and protection of sensitive information
- Logging, monitoring and incident management
- Supplier and third-party risk management
- Backup, recovery and operational resilience
- Secure development and controlled change
- Privacy and responsible-AI governance
