VerSpecifyTM

Security Overview

Company
VERSPECIFY, LLC
Effective date
August 21, 2026
Version
security-v1
Website
https://verspecify.com
Contact
support@verspecify.com
Address
29350 Lisa Lynn Drive, Livingston, LA 70754

This overview describes controls currently implemented for the Service. It is not a guarantee that security incidents cannot occur.

Current controls

  • Tenant isolation: company/workspace data access rules preventing cross-customer access.
  • Identity and access: unique accounts, role-based access, administrator controls, secure sessions, and optional MFA when available.
  • Encryption: TLS in transit and provider-supported encryption at rest.
  • Secrets: server-side storage of API keys; no client exposure; rotation and least privilege.
  • Logging: authentication, permission, document, report, policy-acceptance, and administrative events with protected retention.
  • Secure development: dependency updates, code review, testing, vulnerability remediation, and separated development/production environments.
  • Resilience: database backups, restoration tests, worker leases/checkpoints, and incident response.
  • Vendor risk: maintained subprocessor inventory and review of contractual privacy/security commitments.
  • Data lifecycle: configurable deletion, retention periods, and documented backup expiration.

Security contact

Report suspected vulnerabilities or incidents to support@verspecify.com. Include sufficient detail to reproduce the issue. Do not access other customers' data, disrupt production, or publicly disclose an issue before a reasonable remediation period. VerSpecify welcomes good-faith security reports but does not authorize access to another customer's data, disruption of production systems, privacy violations, or public disclosure before a reasonable remediation period.