ProductsSolutionsPlatformTrustCompanyBook a demo
Trust Center

Everything a security reviewer will ask.

Stated plainly, including where the answer is "we don't have that yet." Nothing on this page is a badge we haven't earned.

Verifiable artifacts

The things a reviewer can actually check.

Swipe for more

Security posture

Several products run air-gapped with zero-egress code paths, so you can inspect their behaviour inside your own environment. Signed outputs verify offline against public keys — verification never requires trusting our servers.

Documented · reviewable under NDA

Compliance status

We hold no certification we have not completed, and we display no badge we have not earned. If you don't see an attestation here, we don't have it — and we won't imply otherwise. When a formal audit begins or completes, its exact status and scope will be stated on this page.

No certifications claimed

Release signing

Verification outputs are cryptographically signed — Ed25519 for off-chain reports, secp256k1 for on-chain verdicts, with domain separation and monotonic nonces where replay matters. Public keys are published so any party can verify independently.

Ed25519 · secp256k1

SBOM & supply chain

Generating software bills of materials is a core capability of VerditNxtGen, and we apply the same expectation to ourselves: an SBOM is available for our own distributed artifacts on request during technical due diligence.

syft-generated · on request

Responsible disclosure

If you believe you've found a vulnerability in any OneZero product, contact us before disclosing publicly. We commit to acknowledging within two business days, keeping you informed, and crediting you if you'd like. We will not pursue legal action against good-faith research.

Report via Contact

AI governance

Language models are used as hypothesis generators only — never as the sole basis for a verdict. Deterministic rules and evidence graphs decide first, seeded knowledge is labelled and capped, and unprovable inputs return UNKNOWN rather than a guess.

Model proposes · rules decide

Privacy & data handling

Causa's ingestion contract is payload-free by schema — structure, never content. Verdit CLI has zero network egress. BizOpsTool never requests invoices or billing access. Where we do process personal data, a formal privacy notice is provided during onboarding.

Payload-free · zero-egress paths

Service status

Air-gapped and self-hosted deployments have no dependency on our availability by design. For hosted services, current status and any incidents are shared directly with customers under their support terms.

Shared under support terms
Evidence & credibility

What we can show you today — and what we can't yet.

Enterprise buyers reasonably want proof from other customers. Here is exactly where we stand, marked honestly.

Available
Example evidence bundles

Real signed artifacts in the exact format the products emit, verifiable offline against our published keys.

Available
Live demo on your system

We run the product against a workload of yours rather than a canned dataset — the most direct proof available.

Available
Source-level technical review

Architecture, threat model and code walkthrough under NDA, including the limits.

Available
Reproducible test results

The Axiom oracle's on-chain test matrix and Verdit CLI's evaluation harness can be run by you, not just described.

Not yet
Named customer case studies

We have none we can publish, so we publish none. When a customer agrees to be referenced, they'll appear here by name.

Not yet
Adoption & deployment metrics

We won't publish counts until they're measured and meaningful. An impressive number we can't substantiate is exactly what this company exists to catch.

Every item marked “Not yet” will move to “Available” the day it's true — and not a day earlier.

Due diligence

Ask us the hard question.

Technical detail for a security review is available under NDA. If we can't evidence something, we'll tell you that instead of talking around it.