Skip to content

TRUST CENTER

Security, compliance & AI governance.

Workforce data is the most sensitive data a company holds. Here is exactly how Humavera protects it — and how the AI is kept on a leash.

ISO 27001 CERTIFIED GDPR COMPLIANT EU DATA RESIDENCY

COMPLIANCE

ISO 27001 certified
GDPR compliant
EU data residency — AWS Europe, end to end

ENCRYPTION

TLS 1.2+ for all data in transit
AES-256 encryption at rest
Field-level encryption for sensitive payloads

ACCESS

SAML 2.0 / OIDC SSO with test-before-activate
Granular role-based access control
Full audit logs on every access and change

AI GOVERNANCE

Six controls, built into the write path.

Plan · preview · approve

Before every write, Vera presents the full plan. A person approves it — or nothing happens.

No credential forwarding

Vera never holds your credentials. Every action uses a short-lived, per-action token.

Server-side permission scoping

Vera can only see and do what the requesting user is permitted to. Enforced on the server, not in the prompt.

Compensating rollback

Every executed plan carries its reversal. One click restores the prior state.

Complete audit trail

Instruction, plan, approver, actions, timestamps — every step recorded, exportable, immutable.

Anthropic models, data protected

Customer data is never used for training and is processed transiently.

Humavera Vault

Humavera Vault ships Q3 2026. Designated employee PII stays on your infrastructure — the platform and AI operate on tokenized references only. Built for organizations whose data cannot leave their territory.

// tokenized reference
name: vault:ref/7f3a…c91
national_id: vault:ref/2b8e…d04
salary_band: B3
pii → your infrastructure
platform → references only

Your security team will have questions.

Good. We have the documentation ready.

Request Security Documentation