Skip to content
veetso.
Trust

Built to be verifiable, not vouched-for.

Trust at Veetso is the sum of artefacts a third party can examine without us in the room: the gates, the audit log, the frameworks, the vendor list, and the public corporate record. Every claim on this page links to its evidence.

  1. Governance

    Six gates clear every AI workflow.

    Every AI workflow at Veetso clears six controls before it touches a regulated process. Each is documented, owned by a named person, and verifiable from the audit log. None is optional, and none is paperwork for its own sake.

    • ·Use-case registration
    • ·Data classification
    • ·Access scoping
    • ·Source attribution
    • ·Human oversight
    • ·Vendor due diligence
  2. Auditability

    A hash-chained audit log is the system of record.

    Every query, source match, gate check, draft, and approval writes to an append-only log. Each entry's hash is computed over its contents plus the previous entry's hash, so tampering is visible by inspection rather than requiring an audit. A regulator can verify the chain end to end without trusting our word.

  3. Compliance posture

    Frameworks we map to, with dates we publish.

    We design to the controls expected of a regulated institution and pursue certifications on a published schedule. Attestation documentation is available to partners and regulators under NDA.

    • ·ISO 27001: in scope for 2026
    • ·SOC 2 Type II: in scope for 2026
    • ·UK GDPR / EU GDPR: ongoing
    • ·PCI-DSS v4.0: applied where in scope
    • ·DORA: preparation underway
  4. Source attribution

    Every Brain answer ships with a citation.

    Internal Brain answers carry a citation back to the document, the revision, and the paragraph the answer came from. Drafting mode is marked as drafting and refused as citable fact downstream. The user sees the chain inline; the audit log records it; a regulator who asks sees the same.

  5. Vendor oversight

    Every AI vendor passes a documented review.

    Each AI model provider and infrastructure supplier passes a documented review covering security, residency, retention, sub-processors, no-training contractual basis, and incident response. The approved vendor list is the only one workflows may use. Renewals require fresh evidence.

  6. Corporate record

    A verifiable legal entity, on the public register.

    Veetso is operated by VEETSO LIMITED, a private company limited by shares registered in England and Wales as company number 16062618. The registered office is 1 Canada Square, Canary Wharf, London E14 5AA. Officers, filings, and registered address are publicly verifiable on the UK Companies House register.

  7. Disclosure

    Security issues go to security@veetso.com.

    We acknowledge security disclosures within one business day. Coordinated disclosure is appreciated, and we credit researchers publicly with their permission. RFC 9116 security.txt is published at /.well-known/security.txt with the same contact details.

For partners and regulators

Documentation available on request.

Audit packs, control-mapping documents, and vendor due-diligence files are available to partners and regulators under NDA. Write to info@veetso.com with a short note about the use case.