Security Overview
- Company
- VERSPECIFY, LLC
- Effective date
- August 21, 2026
- Version
- security-v1
- Website
- https://verspecify.com
- Contact
- support@verspecify.com
- Address
- 29350 Lisa Lynn Drive, Livingston, LA 70754
This overview describes controls currently implemented for the Service. It is not a guarantee that security incidents cannot occur.
Current controls
- Tenant isolation: company/workspace data access rules preventing cross-customer access.
- Identity and access: unique accounts, role-based access, administrator controls, secure sessions, and optional MFA when available.
- Encryption: TLS in transit and provider-supported encryption at rest.
- Secrets: server-side storage of API keys; no client exposure; rotation and least privilege.
- Logging: authentication, permission, document, report, policy-acceptance, and administrative events with protected retention.
- Secure development: dependency updates, code review, testing, vulnerability remediation, and separated development/production environments.
- Resilience: database backups, restoration tests, worker leases/checkpoints, and incident response.
- Vendor risk: maintained subprocessor inventory and review of contractual privacy/security commitments.
- Data lifecycle: configurable deletion, retention periods, and documented backup expiration.
Security contact
Report suspected vulnerabilities or incidents to support@verspecify.com. Include sufficient detail to reproduce the issue. Do not access other customers' data, disrupt production, or publicly disclose an issue before a reasonable remediation period. VerSpecify welcomes good-faith security reports but does not authorize access to another customer's data, disruption of production systems, privacy violations, or public disclosure before a reasonable remediation period.