Resources · Security & Trust
Built for the world's most
sensitive workloads.
Security is a property of the platform, not a feature bolted on. Data sovereignty, zero-trust access, AI guardrails and audit are enforced on every request, wherever you deploy.
Trust pillars
Six commitments,
enforced by design.
Your data stays where your mandate requires: on-prem, in your private or national cloud, or fully air-gapped.
Every request is authenticated and authorized: SSO, MFA and least-privilege roles.
Encrypted in transit and at rest, with managed secrets and key rotation.
Prompt-injection screening, PII redaction and clearance checks run on every AI request, in and out.
Isolated tenants with independent policies, quotas and data: row-level security and attribute-based access.
An audit ledger and traces record every significant event. Provable, not just logged.
Defense in depth
Security at every layer.
Controls are layered from the perimeter to the audit ledger. A failure at any single layer is contained by the next.
Perimeter
Identity & access
Data protection
AI guardrails
Assurance
AI security
Governed AI, by default.
No application ever calls a model directly. Every AI request passes through the governed control plane, where policy is enforced before and after inference.
No Direct Model Calls
Applications call the AI Service Bus, never a model. Routing, policy and audit can never be bypassed.
Prompt-Injection Screening
Inputs are screened for injection and manipulation before they reach a model.
PII Detection & Redaction
Sensitive data is detected and masked before the model sees it, and checked again on output.
Sensitivity Routing
Classified or sensitive workloads route only to permitted models, on-prem or air-gapped when required.
Human-in-the-Loop
Approval gates hold high-impact actions for a person to review before they execute.
Full Traceability
Every decision ties back to its inputs, policy and model on an audit trace.
Compliance & frameworks
Designed to support
your obligations.
The platform is built to help you meet recognized governance and security frameworks. Framework alignment supports your compliance program. It does not replace your own assessment.
Certifications & attestations
Formal certifications and third-party attestations are placeholders, provided on request and added here as completed. We do not claim certifications we do not hold.Controls
The controls your
security team expects.
Sovereignty
Run it where your
data must live.
From public cloud to fully disconnected, on-host deployments: your models, your data, your jurisdiction.
Report a vulnerability
If you believe you've found a security issue, we want to hear from you. Email our security team at security@veevra.com with details and steps to reproduce, and we'll respond promptly.
Security documentation
We share our security overview, architecture and deployment details with prospective and existing customers under NDA. Request a copy and we'll set up a session with our security team.
Evaluating VEEVRA for a
regulated workload?
We'll walk your security and compliance teams through the model, controls and deployment options in detail.
