Trust centre

Security is non-negotiable.

Your contracts are among the most sensitive documents you hold. This page states exactly how they're protected, who processes them, and what happens if something goes wrong. No vague promises, and no separate page for the parts that are harder to answer.

SOC 2 Type II
Infrastructure audited to SOC 2 standards
AES-256
At rest, with TLS 1.2+ in transit
UK and EU only
No data transferred outside the UK and EU
Zero training
Your contracts never train an AI model
OUR DATA COMMITMENT

Contract data is never used for AI model training. Uploaded contracts and review outputs are processed solely to fulfil your review request, and both model providers we call operate under API data processing addendums that contractually prohibit training on customer data.

The lifecycle

One document, start to finish.

Six stages, from the moment a contract reaches us to the moment it stops existing. Every claim below is answered in more detail further down this page.

01 · IT ARRIVES

Over TLS 1.3, from the app, the add-in, a forwarded email or an API key.

02 · IT'S CLAIMED

Bound to your organisation before anything reads it. Unrecognised senders are rejected, not quarantined.

03 · IT'S ANALYSED

Under contracts with our model providers that give no training rights and no retention.

04 · IT'S STORED

Encrypted at rest in the UK and EU, in storage no other tenant can address.

05 · EVERY LOOK IS LOGGED

Attributed to a person or a key, exportable by your admins.

06 · IT'S DESTROYED

On your retention schedule, or the day you leave, documents and object storage both.

RESIDENCY
The UK and EU
TRAINING
Never on your data
ISOLATION
Enforced in the database
STAFF ACCESS
Reason, timer, log
The questions procurement always asks

Answered without the hedging.

If your form needs these in its own wording, send it over, we fill in questionnaires ourselves rather than making you chase.

Do you train models on our contracts?

No. Not us, and not the model providers we call, that’s a contractual term with them, not a setting. Nothing you send becomes training data for anyone, and we don’t keep your clause text to improve the product.

Can your staff read our contracts?

Only with a reason recorded, for a limited window, and it lands in the audit log you can export. It happens when you ask us for help with a specific review. Nobody browses customer contracts, and there is no path to do it quietly.

Where is it processed and stored?

The UK and EU, on named sub-processors listed below. If a change would move your data outside that, you hear about it before it happens rather than in a changelog afterwards.

How do you keep tenants apart?

Row-level security in the database, so isolation doesn’t depend on application code remembering to filter. Quotas, feature gates and API scopes are enforced server-side on the same basis, including for the assistant connector.

Who sees a contract sent for expert review?

The reviewer assigned to that one deal, and only for as long as it’s with them. They’re under confidentiality terms with us, their access ends when the revision is released, and it’s all in the log.

What happens if something goes wrong?

Your admins are told within two hours of us confirming an incident that affects your data, what we know, what we don’t yet, and what we’re doing. A full report with root cause and impact follows within 72 hours, and the ICO is notified where required.

Access

Who can see what, exactly.

Four kinds of people touch a review, and only one of them is us.

SWIPE THE TABLE →
Admin Member Approved sender Expert reviewer Vern staff
Contracts and reviews All All Their own One deal On request
Playbooks and positions Edit View None That review On request
Credits, usage and invoices All None None None Totals only
Seats, senders and API keys Manage None None None None
Audit log Export None None None With you

"On request" is the honest version of support access: you ask for help, an engineer gets a time-boxed grant with the reason attached, and the grant itself appears in your audit log. Approved senders never get an account, they forward a contract from an address you've allowed and get the review back.

IN TRANSIT AND AT REST
Encrypted both ways
TLS 1.3 in transit, AES-256 at rest
Documents in object storage, not in the database
Signed, expiring URLs for every download
Secrets in a managed store, rotated
TENANT ISOLATION
Enforced below the app
Row-level security on every table
API keys & assistant tokens scoped to one org
Quotas and feature gates checked server-side
SSO and MFA available on request
AUDITABILITY
Everything is attributable
All reviews, view & export logged to a person or key
Playbook changes versioned, with who and when
Webhooks signed with HMAC and a replay window
Admins export the log themselves, any time
AI processing

What actually happens to a document you upload.

The analysis calls a model provider. That is the part people want to understand properly, so here it is in plain terms rather than buried in a policy.

No training on your data, ever

Your data goes in, your report comes out, and nothing is retained for training. That is a contractual term with our providers rather than a setting we could quietly change.

EU-based processing

AI providers process data via EU-based endpoints, and sub-processor agreements include Standard Contractual Clauses where applicable.

Human review stays optional

Outputs are review indicators to assist a human decision. They are not automated decisions with legal effect, and you can ask for human review at any point.

Transparency

Every third party that touches your data.

Listed here rather than on request, with 30 days' notice before any change.

PROVIDERPURPOSELOCATION
OpenAI
Contract analysis
EU
Anthropic
Contract analysis
EU
LlamaIndex
Document parsing
EU
Managed cloud platform
Application hosting
EU
Clerk
Authentication
EU
Stripe
Payment processing
UK/EU
Resend
Email delivery
EU

Legal entities and the current agreements are annexed to the DPA. Adding or replacing any of these is notified in writing 30 days beforehand.

The paperwork

What we can put in front of you.

All of it exists today and you can have it on the call rather than after a procurement cycle. Ask for a certificate, a completed questionnaire or the sub-processor list and it comes back the same week.

AVAILABLE NOW
DPA and SCCs

Signed as part of onboarding, with sub-processors named and change notice in writing.

AVAILABLE NOW
Questionnaires

Send us yours and we complete it. A founder answers it, so the replies are specific.

AVAILABLE NOW
Audit exports

Your admins pull the full log themselves, including on the way out. No ticket, no waiting on us.

CERTIFIED INFRASTRUCTURE
SOC 2 and ISO 27001

Vern runs on infrastructure holding SOC 2 Type II and ISO 27001, audited annually. Certificates and the current scope are available on request.

LEAVING
Deletion that actually deletes

Offboarding purges your documents and object storage in full, not a soft delete with a flag on it. You take audit exports and your playbooks on the way out, and we keep only what we're legally required to keep for invoicing.

Retention period set per organisation
Delete a single contract at any time, permanently
Data subject requests handled within statutory time
No card on file, so nothing to cancel
GDPR

Your data rights, and how to use them.

Ask for any of these in one line to the address below. We confirm in writing what we did, within statutory time.

Privacy enquiries privacy@assurepath.co.uk
Data protection officer dpo@assurepath.co.uk
Everything else hello@askvern.ai
Access
A copy of all personal data we hold about you
Rectification
Correction of anything inaccurate or incomplete
Erasure
Deletion of your data, subject to legal obligations
Portability
An export in a machine-readable format
Restrict processing
Limits on how we use your data in specific circumstances
Object
Opposition to processing based on legitimate interests
Incident response

If something goes wrong, this is the order it happens in.

IMMEDIATE
Containment

The incident is detected and contained, and the internal response team is activated.

WITHIN 2 HOURS
You are told

Affected customers are notified with the initial detail and the scope as we understand it.

ONGOING
Updates as we learn

Continuous updates while the investigation runs and remediation is applied, rather than silence until it is tidy.

WITHIN 72 HOURS
Full report

Root cause, impact assessment and preventive measures, with the ICO notified where required.

Bring your security questionnaire to the call.

We'd rather answer it live than send you a PDF that dodges the hard rows. Ask us the awkward ones.