VeriloVerilo
How it worksFAQSecurityLog inStart free trial

Security

How Verilo protects merchants' and their customers' data, and what happens if something goes wrong. Questions and reports: bailee@verilo.app.

Encryption

Every connection to Verilo uses HTTPS. The database and the storage for recordings are encrypted at rest by our providers. The keys Verilo holds for a merchant's Shopify, Gorgias and Zendesk accounts are encrypted again with a separate key (AES-256-GCM) that lives only in the production secret store.

Access

Each merchant sees only its own claims, orders and evidence; every request is checked against the merchant it belongs to. Verification links are signed and stop working after 72 hours. Production access is limited to the person who runs Verilo. Every sign-in, claim, result, decision and deletion is written to an audit log that cannot be edited.

Evidence integrity

Each recording and photo is stored with its SHA-256 fingerprint and checked on arrival. Evidence cannot be edited after it is captured; it is only ever deleted as a whole, or under the retention period.

Data loss prevention

Customer data stays in the database and storage listed in our Privacy Policy. Our logs record identifiers, never recordings, photos or message text. Diagnostic logging that records more detail runs only in development, never in production. Secrets are never stored in source code. Our database provider keeps continuous backups.

Retention

Recordings and photos are deleted automatically 90 days after capture unless the merchant extends it (up to one year). Results and the audit log are kept. When a store uninstalls Verilo, Shopify tells us 48 hours later and we delete that store's claims, evidence, orders and settings; when Shopify asks us to erase one customer's data, we delete their claims and evidence and their name and email.

Incident response

If we find or are told of a security incident, we act in this order:

1. Contain it: revoke exposed keys, close the gap, and keep evidence of what happened.

2. Assess it: what data and which merchants are affected, and whether it is an eligible data breach under the Notifiable Data Breaches scheme.

3. Notify: affected merchants within 72 hours of becoming aware, with what we know; the Office of the Australian Information Commissioner and affected individuals where the scheme requires it.

4. Learn: record the incident and its cause, and fix the cause.

Reporting a vulnerability

Email bailee@verilo.app with "Security" in the subject. Please give us a reasonable time to fix an issue before disclosing it. We will acknowledge your report within 3 business days.

Bailee Satie trading as Verilo · ABN to be added · bailee@verilo.app

VeriloVerilo

Every damage claim, verified.

Terms of ServicePrivacy PolicyData Processing AgreementSecuritybailee@verilo.app

© 2026 Bailee Satie trading as Verilo · ABN to be added