Security principles
- Minimum necessary access. Connections and roles are scoped to the work the product needs to perform.
- Traceability. Findings preserve source context so users can inspect how an output was reached.
- Human accountability. Veracourse prepares evidence and options. Authorised people record decisions.
- Secure defaults. Transport encryption, protected credentials and restrictive browser security headers are part of the production baseline.
Protecting data
Traffic to the production service is protected with TLS.
Production databases and object storage use encryption at rest.
Primary production infrastructure runs on Amazon Web Services in the European Union.
Versioning and backups support recovery while retention is limited through operational schedules.
Customer workspace data is not used to train shared models.
Access and workspace isolation
Application access is authenticated and authorised by workspace role. Data operations are scoped to the active workspace, and administrative access is restricted to approved operational purposes.
Where supported, source connectors request read-only access. Secrets are kept outside application source code and access events are logged for operational review.
Secure operations
We monitor application health and security-relevant events, retain routine service logs for a limited period, maintain production backups, and apply updates through a controlled deployment process. Security claims are reviewed as the architecture changes.
We assess reported issues, contain credible threats, restore safe service and notify affected customers or authorities where applicable law or contract requires it.
Report a security issue
Email support@relentlesspowertechhouse.com with a concise description and a safe way to reproduce the issue. Do not access another customer's data, disrupt the service, or include live credentials in your report.
We will acknowledge credible reports and coordinate next steps. Please allow reasonable time to investigate before making details public.