Security & Compliance

At VeraPiù, security is not an afterthought or an add-on module — it is the architectural bedrock of every line of code we write, every database schema we structure, and every educational ecosystem we deploy.

Effective Date: September 24, 2026
GDPR & EU Data Regulation Compliant
Version 2.4 · Enterprise Master Standard

1. Security Architecture & Philosophy

Educational institutions, technical academies, and enterprise systems manage highly sensitive personal records, academic evaluations, financial transactions, and operational communications.

Our engineering approach implements a Zero-Trust Architecture. Every API request is verified, every database query is policy-checked at the kernel layer, and every administrative action is logged to an immutable audit record.

99.9%Uptime SLA Target
AES-256Encryption at Rest
TLS 1.3Encryption in Transit

2. Cryptographic Encryption Standards

Data in Transit

All communications between client devices (web browsers, iOS/Android native apps) and VeraPiù API endpoints are strictly enforced over TLS 1.3 (with fallback to TLS 1.2 minimum). Unencrypted HTTP traffic is permanently blocked using HTTP Strict Transport Security (HSTS) with preloading.

Data at Rest

All primary databases, backups, object storage buckets, and document repositories are encrypted using hardware-accelerated AES-256 encryption with rotating cryptographic key management protocols.

Password Hashing & Secrets

User credentials are salted and hashed utilizing memory-hard bcrypt / Argon2 algorithms. Cleartext passwords are never visible, stored, or accessible by VeraPiù engineers.

3. Multi-Tenant Isolation & Database RLS

A critical vulnerability in legacy school management platforms is cross-tenant data leaks. VeraPiù resolves this architecturally:

• PostgreSQL Row-Level Security (RLS): Data isolation is enforced at the database engine level, not in application middleware. Every query executed includes cryptographically verified tenant identifiers (`organization_id`).

• Strict Role Isolation: Students can never access teacher gradebook drafts; families can only access verified records of their own enrolled dependents; administrators access only their assigned institutional purview.

• Option for Dedicated Database Instances: Enterprise institutions can request logically or physically isolated dedicated database clusters within the Frankfurt, EU region.

4. Authentication & Access Governance

Access governance is calibrated to protect academic stakeholders while preserving streamlined daily workflows:

  • Multi-Factor Authentication (MFA): Supported via TOTP authenticator apps (Google Authenticator, Apple Passwords, 1Password) and hardware security keys.
  • Single Sign-On (SSO): SAML 2.0 and OpenID Connect (OIDC) support for Google Workspace for Education and Microsoft Entra ID (Azure AD).
  • Granular RBAC: Permission sets are customized down to specific administrative actions (e.g. attendance editing vs view-only, grade publication triggers).

5. Edge & Cloud Infrastructure Security

Our production environments leverage world-leading infrastructure with global redundancy:

DDoS Mitigation & WAF

Protected by Cloudflare enterprise network with unmetered Layer 3/4/7 DDoS mitigation, managed web application firewall rules, and rate-limiting against brute force attacks.

EU Data Sovereignty

All database instances and application servers storing institutional data are located within the European Union (Frankfurt, Germany), guaranteeing complete alignment with EU data sovereignty standards.

6. Backups, Redundancy & Disaster Recovery

We maintain resilient business continuity and disaster recovery procedures:

• Continuous Point-in-Time Recovery (PITR): Database changes are continuously streamed to encrypted archive storage, allowing recovery to any second within a 30-day window.

• Daily Automated Full Snapshots: Stored across geographically separated availability zones.

• RPO / RTO Targets: Recovery Point Objective (RPO) < 5 minutes; Recovery Time Objective (RTO) < 2 hours.

7. Vulnerability Disclosure & Bug Bounty

We welcome collaboration with independent security researchers and ethical hackers. If you discover a potential vulnerability within any VeraPiù web property, service, or API:

1. Please email full reproducible technical details to security@verapiu.com.

2. Provide reasonable time for remediation before any public disclosure.

3. Do not access, modify, or exfiltrate client or student data during testing.

We review and acknowledge eligible reports within 24 business hours and offer rewards and formal recognition for valid, responsible vulnerability submissions.

8. Regulatory Compliance Frameworks

VeraPiù aligns with major international data privacy and security benchmarks:

GDPR (EU 2016/679)Comprehensive compliance with European data subject rights, DPIAs, and Article 28 DPAs.
SOC 2 Type II AlignmentInfrastructure partners certified for Security, Availability, and Confidentiality trust principles.
ISO/IEC 27001 ControlsAdoption of information security management system (ISMS) policies and continuous risk reviews.
FERPA / COPPA PrinciplesArchitected to safeguard student academic records with parental oversight and zero behavioral tracking.

VeraPiù Legal & Data Protection Office

For formal data subject requests, law enforcement inquiries, or customized Data Processing Addendums (DPA) for your school or enterprise:

General Legal Counsellegal@verapiu.com
Data Protection Officer (DPO)dpo@verapiu.com