Trust & Security

Last updated: 2026-07-10

This page is for procurement, security and legal teams evaluating VeriFluent. It sets out the controls that protect your documents — honestly. We describe what is true today and are explicit about what is on the roadmap rather than claiming certifications we do not hold.

  • UAE data residency — documents stored and processed on UAE-based infrastructure
  • No training on customer data — your documents and translations never train any AI model
  • Tenant isolation enforced in every query and storage operation
  • Watermarked view-only preview — original document bytes never leave your control
  • Tenant-scoped audit trail on every upload, translation, review, approval and deletion
  • Retention and legal-hold controls on your documents
  • Write-only secret handling — secrets are never exposed back to the browser

Data Residency

Your documents are stored and processed on UAE-based infrastructure, providing genuine in-country data residency for organizations that require their data to stay in the United Arab Emirates. Translation runs through configured AI providers under our platform controls, and each job snapshots the provider and settings in force when it runs.

No Training On Your Data

We do not use your documents or translations to train, fine-tune or improve any AI model. Content is processed to complete the specific translation job you requested and nothing else. This constraint applies to the AI providers we use as well as to VeriFluent.

Tenant Isolation And Access Control

Every document, job and comment is sealed to your workspace and isolated from every other tenant — isolation is explicit in each query and object-storage operation, including any platform-level administrative action, which is metadata-only and produces a tenant-scoped audit record. Access is governed by roles, so people see only what their role permits.

Watermarked View-Only Preview

When a document is shared for viewing, the in-browser preview is watermarked and view-only. A view-only recipient never receives the original file bytes — the original stays under the control of the people you authorize to download it. This lets you route documents for review without handing over the source file.

Audit Trails, Retention And Legal Hold

Every meaningful action — who uploaded, translated, reviewed, approved and deleted, and when — is recorded in a tenant-scoped audit trail. Documents are subject to retention and legal-hold controls so you can keep records for as long as you need and preserve them when required. Audit records can be exported for your own compliance needs.

Secrets And Credentials

Secrets are handled write-only: provider keys and credentials are stored through a secret manager and are never returned to the browser or stored in plain form. Read views show only a masked value, a fingerprint and status — enough to manage a credential without ever re-exposing it. A saved provider key is not treated as ready until a real validation check succeeds.

Compliance Roadmap

We are deliberate about not overstating our compliance position. VeriFluent is not currently certified under SOC 2 or ISO 27001. A SOC 2 Type II program is a roadmap objective, and we are building toward the controls and evidence it requires. If your procurement process needs specific documentation or a security questionnaire completed, contact us and we will share what we can substantiate today.

Enterprise Controls On The Roadmap

Single sign-on (SSO) connection configuration, SCIM user provisioning, and a downloadable compliance-export bundle are enterprise features on our roadmap rather than shipped today. We will describe their status honestly during procurement. If one of these is a requirement for you, let us know so we can prioritize and give you a realistic timeline.

Explore more

Common questions

Is VeriFluent SOC 2 certified?
Not today. VeriFluent is not currently SOC 2 or ISO 27001 certified. A SOC 2 Type II program is on our roadmap and we are building toward it. We would rather tell you that plainly than display a badge we do not hold.
Do you support SSO and SCIM?
SSO connection configuration and SCIM provisioning are on the roadmap and not shipped yet. The platform already proves identity through configurable auth providers; the self-service SSO connection UI and SCIM are the parts still in progress. Tell us your requirement and we will give you a realistic timeline.
Can you complete our security questionnaire?
Yes — contact support@verifluent.ai and we will complete what we can substantiate today and be clear about anything that is still on the roadmap.

See your own document translated

Bring a real document and we will translate it with the layout fully preserved.

Request A Demo