Veriquo stores your security evidence and can read your accounts. That makes our
posture the product's credibility, so we built it the way a bank would demand.
Read-only, least privilege
The collector assumes a role you deploy, scoped to Describe, List, and Get. It can never
mutate anything in your account, because the permission to do so was never granted.
One-directional trust
Your accounts trust our collector to read. Nothing in our account is assumable from yours, and a
leaked role ARN is useless without the per-tenant ExternalId that pins it to you.
Per-tenant isolation you can prove
Every row, artifact, and collector run is scoped by tenant, under per-tenant KMS envelope
encryption. Customer-held keys and crypto-shred on offboarding are available, ported from Eliquo.
WORM, hash-chained, checkpointed
Evidence is written once under S3 Object Lock and hash-chained. A weekly checkpoint anchors the
chain, so tampering is detectable, not merely against the rules.
A collector account we hardened first
The account that holds the keys to customer clouds runs its own compliance program on this
platform. We dogfood the product, so our own SOC 2 evidence is gathered by the thing you are buying.
A page with nothing to disclose
This site loads no third-party scripts, no analytics, no cookies, and no consent banner. It is one
self-contained file your security team can read end to end. The posture starts at the front door.