The service is operated by Verand (“Verand”, “we”, “us”), a trading name of Brussel Investments, Inc., a Wyoming corporation. Security questions and vulnerability reports: security@verand.ai.
Our customers are businesses, and what we hold is business data: the websites you ask us to analyse, the briefs and drafts we produce, your author profiles, your brand and voice settings, and whatever you add to your knowledge base. Alongside that we hold account data (your name, work email, and the organisation and sites you add) and product and diagnostic data (log entries, error reports and aggregate usage events).
We don’t buy, scrape or assemble personal data about members of the public, and we don’t operate a consumer service. Card numbers never reach us: billing runs through our payment processor, and we store a customer identifier, plan and invoice history.
The full account is in the Privacy Policy. This page is the shorter version a security review usually needs.
We don’t train models on your content, and neither do the model providers we call. Your articles, your knowledge base and your site data are processed to produce your output, and nothing else.
Both halves of that sentence matter, and they’re different kinds of promise. The first is ours. The second is contractual: the model providers Verand calls don’t train on API inputs by default, which is a term you can verify in their own published API terms rather than take on our word.
Where figures from your connected accounts are passed to our AI subprocessor to produce a recommendation for you, for instance when explaining why a page is underperforming, that processing happens under terms that prohibit the subprocessor from using the data to train its models.
We don’t sell your data, transfer it to data brokers, use it for advertising or credit purposes, or use it to train generalised AI or machine-learning models.
Nothing is published to a live site without an explicit human action in Verand. Verand produces drafts, runs automated checks against them, audits websites and prepares changes for your review. The approval is yours, every time.
- Google Search Console and Google
Analytics 4 are connected read-only, under
webmasters.readonlyandanalytics.readonly. We cannot and do not modify anything in either account. - Google Business Profile, where you connect a listing you control, is read in order to audit it. We write only the items you have explicitly approved, and we never automatically change a listing’s name, address, phone number, categories or hours.
- A content management system or code repository is accessed only as far as is needed to read the pages you ask us to analyse and to submit drafts for your approval.
You can disconnect any integration at any time under Settings → Integrations, and you can revoke Verand’s Google access directly at myaccount.google.com/permissions. On disconnection we stop all further access immediately and delete the stored credentials.
We use a small set of vendors to run the service. Each is bound by contract to protect the data they process on our behalf, and none of them receives your content for any purpose other than delivering the part of the service they provide.
The current list, naming each vendor and what it processes, is available on request at security@verand.ai. We send it to customers and to anyone running a vendor review. Ask and you’ll have it the same day.
Two things are worth stating without waiting for the request. Our AI model providers do not train on your content. And the market-data sources behind keyword, ranking and competitor figures receive a domain, a keyword or a competitor’s URL, never your content and never personal data, which is why they sit outside this list rather than inside it.
Where Google user data is involved, the vendors that touch it and our Google API Limited Use commitments are set out in full in the Privacy Policy.
Data is held on managed cloud infrastructure in the United States, encrypted in transit with TLS and encrypted at rest. Access to production systems is restricted to personnel who need it. Third-party credentials and OAuth tokens are stored encrypted and are never exposed in the browser.
Your data is scoped to your organisation and isolated from other customers by row-level access rules enforced in the database itself, rather than by application code alone.
We operate from the United States and store data with providers located in the United States. If you are outside the United States, using the service transfers your personal data there, where it may be subject to lawful access requests by United States authorities. Where that transfer requires a legal mechanism, for customers in the UK, the EEA or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, available on request at support@verand.ai.
- Account and content data is retained while your account is active.
- On cancellation, data is deleted within 30 days, other than records we must keep for tax and accounting purposes.
- Disconnecting an integration deletes its credentials immediately and its retrieved data within 30 days.
- You can request deletion at any time at support@verand.ai. We respond within 30 days.
This is the commitment published in the Privacy Policy, restated here unchanged.
Verand sells to people whose own regulators ask them awkward questions, so the useful thing to publish is the list of things we can’t say. Today it’s a long list.
- SOC 2. Verand does not hold a SOC 2 report of either type, and we’re not going to write that one is in progress when it isn’t.
- ISO 27001. Not held.
- Penetration testing and bug bounty. There’s no third-party penetration test report to send you and no bug bounty programme.
- SAML single sign-on. Not available today. If SSO is a requirement of your review, say so before you buy rather than after.
- VPAT. We haven’t pre-commissioned an accessibility conformance report. We’ll produce a scoped one on request.
The reason to publish that list rather than soften it is the same reason our compliance packs say “AI researched and operator reviewed” instead of “attorney verified”. A trust label that overstates who did the work is worse than no label.
Verand ships a HIPAA compliance pack. It governs article content, what a medical or dental practice may and may not say in published marketing, and it is not a statement that Verand handles protected health information.
Verand does not process PHI, is not a business associate, and does not offer a Business Associate Agreement. Offering one would imply a data flow that doesn’t exist and shouldn’t. Don’t put patient information into a brief, a knowledge base entry or a draft.
If a security incident affects your data, we’ll tell you. You’ll hear from us at the contact address on your account, without undue delay, with what we know at the time and what we’re doing about it.
We’d rather send you an early message that is incomplete than a tidy one that is late. If the picture changes after we write to you, we’ll write again.
If you’ve found a security problem in Verand, send it to security@verand.ai. Include what you did, what you saw, and anything that would let us reproduce it. There’s no bug bounty programme and no paid reward. Send it anyway.
Brussel Investments, Inc., d/b/a Verand
1718 Capitol Ave, Cheyenne, WY 82001, USA
Security: security@verand.ai
Everything else: support@verand.ai
Sending a security questionnaire? Send it to the address above. We answer them, and we answer “no” where the answer is no.