Trust center

Built so you don't have to trust us.

Verillian runs on your hardware. It seals its record under your keys. It never receives your data. Most of what a vendor usually asks you to take on faith simply isn't here. This page holds the rest: what we align to, how it's built, what we won't claim, and the paperwork your review will ask for.

01
Standards

Aligned to the frameworks you answer to.

Aligned, not certified: Verillian builds to these controls, and whatever your framework calls the final word, certification, authorization, or attestation, it stays yours to earn in your own environment.

02
How it's built

Built in, not promised.

Six properties do most of the work, and every one is a fact of the architecture rather than a line in a policy document.

It runs on your own hardware

On-prem, private cloud, or fully air-gapped: the governing layer and the record both live inside your boundary, and nothing about running them depends on us.

We never see your data

There's no Verillian cloud for your traffic to pass through. Prompts, responses, and records never reach us, which removes a whole class of vendor risk before the questionnaire even starts.

Every decision lands in a sealed record

Each ruling is signed on the device that made it and linked into a chain, so the record you show an assessor carries its own proof of integrity.

A key only you hold

Records are encrypted under your institution's key. Anyone you authorize can verify they're intact, but reading them takes the key, and we never have it.

Deny by default

Anything you haven't allowed is refused, and a request the policy can't make sense of is refused too, rather than guessed at. The safe answer is the built-in one.

It fails closed

If policy can't be checked or the record can't be written, AI stops. An action you couldn't prove afterwards is one that doesn't run.

  1. prev0000000000000000000000000000000000000000000000000000000000000000
    record 0001 / prompt decided / ALLOWALLOW
    hashde70735cec5245919d1a77a20b07deaf29f204f73d3abda37dd70713af2e6c8a
  2. prevde70735cec5245919d1a77a20b07deaf29f204f73d3abda37dd70713af2e6c8a
    record 0002 / prompt decided / REDACT / 1 token hiddenREDACT
    hash5b54ebd8ce4f7efc059f4a46d18e33ce4c4c2c52f5d69e63680caf2e245d0ba5
  3. prev5b54ebd8ce4f7efc059f4a46d18e33ce4c4c2c52f5d69e63680caf2e245d0ba5
    record 0003 / tool call refused / BLOCKBLOCK
    hash101ac285e576be6e38a01d865ca8b05e7a4c2f0bd37c56ba5ad8d4de9a6de0f2
demo data / three synthetic records
03
Known limits

The limits, stated plainly.

Every control has edges, and a security review deserves them up front rather than in a footnote. Here are ours.

01 / REDACTION

Redaction is best effort

It screens the identifiers your policy flags, from record numbers to name patterns, before a prompt leaves the device. Like any redaction, including one done by a careful human, it is best effort, and everything it caught is visible in the record.

02 / BLOCKING

Blocking covers the Anthropic API format today

Pre-execution tool blocking runs on the Anthropic API format today, the format Claude and Claude Code speak, with more bindings arriving by signed configuration. The other providers your policy names, ChatGPT among them, are captured and sealed into the same chain, screened where the format allows, their tool calls recorded rather than refused. A provider your policy doesn't name isn't governed at all, so deployment starts by naming yours. Ask about a provider and you'll get a straight answer.

03 / CONTAINMENT

Containment stops new actions, not streams in flight

Flipping the switch refuses the next connection and the next call everywhere at once. A response already streaming finishes on its own, and nothing new starts until you say so.

04
Questions

What security teams ask first.

No. There's no Verillian cloud in the path: enforcement happens on your devices and the record seals to a server you run. We couldn't produce your data for anyone, ourselves included, because we've never had it.
It means Verillian is built to the controls in frameworks like CJIS Security Policy v6.1, HIPAA, NIST 800-53, and CMMC, and we document how it maps to each one. Certification belongs to your deployment in your environment, so we hand you evidence instead of borrowing a badge.
Proprietary, licensed per deployment. The software runs entirely in your environment and checks a signed key offline, and everything it seals stays encrypted under keys only you hold, so the license model never touches your data or your uptime.
Yes. Verillian runs with no outside connection at all, which matters in criminal justice and defense work: policy, decisions, license checks, and the sealed record all stay inside your boundary, and enforcement never waits on the internet.
Captured means it crossed the checkpoint on an enrolled device, bound for a provider your policy names. That's the record's boundary, stated plainly: a personal device outside your management, or a provider outside your policy, sits outside the record too, which is why deployment starts by naming both.
The architecture walk-through, control-by-control mappings for the frameworks you name, a completed security questionnaire, and the DPA or BAA if your review requires one. The security overview page holds the reading list, and the rest is a request away.

Need it in writing for a security review?

Tell us which frameworks you answer to, and we'll send the control mappings, the architecture overview, and the agreements, assembled for your reviewer.