Security & Compliance

Security & Compliance

Security, privacy and responsible AI are part of the platform design.

Veriscore uses recognised regulatory and assurance frameworks as reference points for governance, technical safeguards and continuous improvement. The descriptions below distinguish legal obligations, alignment work and independent certification.

Protect Access control, encryption, logging and privacy-focused architecture.
Govern Risk, supplier, incident and AI governance processes.
Improve Controls are reviewed and strengthened as the platform evolves.
Privacy programme

GDPR & data protection

Veriscore is designed around data minimisation, controlled access, security safeguards and support for data-subject rights. GDPR compliance ultimately depends on both technical controls and the organisation operating them correctly.

Consent-focused

Cookies & ePrivacy

Cookie and browser-storage choices are presented separately from essential platform functions. Non-essential technologies should only be activated when the applicable consent requirements have been met.

Readiness

SOC 2

Veriscore uses the SOC 2 Trust Services Criteria as a reference for security, availability, confidentiality, processing integrity and privacy controls. Veriscore does not claim to hold a SOC 2 report unless an independent examination has actually been completed.

Security alignment

NIS2

Risk management, incident handling, resilience, supplier security and access controls are developed with NIS2-style cybersecurity expectations in mind. Whether the legislation formally applies depends on the operating entity, service and legal scope.

Alignment

ISO/IEC 27001

Information-security practices are being structured around risk-based management and controls associated with ISO/IEC 27001. Alignment is not the same as certification; certification requires an audit by an appropriate independent certification body.

AI governance

EU AI Act

AI-supported features are treated according to their purpose and potential impact. Veriscore works toward transparency, human oversight, documentation and risk controls appropriate to AI used in recruitment and professional assessment contexts.

What our framework statements mean

Legal compliance, framework alignment, audit readiness and certification are different things. We use precise wording so customers are not given the impression that an external certification or assurance report exists when it does not.

Official framework and certification logos are not used as decorative trust badges. Where independent certification or assurance is obtained in the future, any mark will be used only under the rules of the organisation that issued it.

Shared controls, not separate security silos

Many good controls support several obligations at once. Strong identity and access management, for example, supports privacy, cybersecurity and assurance requirements simultaneously. Veriscore therefore maintains a common control-oriented approach rather than unrelated compliance projects.

  • Access control and least-privilege principles
  • Encryption and protection of sensitive information
  • Logging, monitoring and incident management
  • Supplier and third-party risk management
  • Backup, recovery and operational resilience
  • Secure development and controlled change
  • Privacy and responsible-AI governance