Soverity

Security at Soverity

At Soverity we take security very seriously. The very reason we exist, is to ensure that your data and infrastructure don’t fall into the wrong hands. We value and follow information security standards and best practice checklists, but we also believe that real security is about more than checking boxes. To build secure software and infrastructure, we understand and model threats and risk, and we apply defense in depth across every layer of the stack.

Responsible disclosure

We welcome responsible disclosure of vulnerabilities in our software and infrastructure. We do not offer financial rewards for reported findings. To report a finding, send an email to security@soverity.eu. If your message warrants strong confidentiality, you can encrypt your message with Age. You can find our public key here.

Compliance

We are well versed in the ISO-27001 and SOC 2 information security standards, and we design our internal policies and processes in line with these standards. We can work with your compliance team to provide them with the documentation they need. Contact us to schedule a call, and we’ll tell you all about our information security program.