Trust Centre
VEYRA Trust Centre
A transparent view of the controls operating today, the controls being strengthened and the certifications VEYRA intends to pursue.
Control status
Security claims should be testable, not implied
Each area carries a plain status. Planned and developing controls are not presented as operating controls.
Information security
PilotSecurity controls are maintained as part of the pilot environment and are being formalised for enterprise assurance.
Privacy
ImplementedPrivacy notices, consent handling and organisation-scoped access are built into the current experience.
Authentication
ImplementedAuthenticated portal access, password recovery and protected routes are in place.
Access control
ImplementedRoles and organisation membership control permitted actions; sensitive mutations are authorised on the server.
Data separation
ImplementedOrganisation-scoped records and storage paths separate buyer and supplier information.
Row level security
ImplementedDatabase policies restrict records by authenticated organisation and role.
Audit logging
ImplementedMaterial procurement, approval and administration events are retained with actor, time and reference.
Backup and recovery
Under DevelopmentRecovery objectives and enterprise operating procedures are being documented and tested.
Incident management
Under DevelopmentFormal incident classification, escalation, communication and review procedures are in development.
Data retention
Under DevelopmentRetention settings are being aligned to customer, legal and evidence requirements.
AI governance
PilotAI assists with parsing, matching and recommendations; human approval remains required for commercial decisions.
Human approval controls
ImplementedAI cannot publish, award, approve payment or make another irreversible commercial commitment.
Subprocessors
Under DevelopmentThe supplier register and customer-facing disclosure process are being prepared for enterprise review.
Compliance programme
Certification roadmap
These are management-system targets, not certifications held by VEYRA.
VEYRA does not display certification marks and does not claim certification until an independent certification body has completed the required assessment.
AI governance
AI assists. People remain accountable.
AI may structure a requirement, suggest catalogue relationships, identify possible supplier matches and prepare a recommendation. It cannot autonomously approve, award or create a binding commercial commitment.
Human control points
- A person approves catalogue matches before publication.
- A buyer confirms requirements before supplier release.
- An authorised role reviews recommendations and approvals.
- Supplier identity is revealed only at the configured stage.
- Commercial decisions and changes are written to the audit record.
Review VEYRA against your assurance requirements
Request a focused session covering access, data separation, audit evidence, AI governance and the control roadmap.
