Security & SOC 2.
At VerifyOne, security is not a feature—it is the foundation of our entire product. When enterprise brands trust us with their entire supply chain verification, we meet that trust with military-grade cryptography and rigorous compliance standards.
SOC 2 Type II Compliant
We are audited annually by a third-party firm to ensure strict adherence to the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. You can request our latest SOC 2 report via your account manager.
End-to-End Encryption
All ledger transactions, from the moment a token is minted to the moment a consumer scans the QR, are encrypted in transit (TLS 1.3) and at rest (AES-256). We utilize rotating salts to prevent brute-force attacks.
Hardware Security Modules
The cryptographic keys used to sign our digital certificates are generated and stored inside FIPS 140-2 Level 3 certified Hardware Security Modules (HSMs) ensuring keys can never be exported or extracted.
Penetration Testing
We conduct biannual penetration testing targeting our consumer app, brand dashboard, and underlying APIs via independent cybersecurity red teams. Summaries are available under NDA.