Trust Infrastructure
Trust = decision + receipt + auditability.
This page documents our infrastructure commitments. Artifacts included.
What we mean by trust
Trust is measurable. It's a permissioned decision under uncertainty - with proof.
Decision
Yes / Conditional / No. Clear, actionable, enforceable.
Receipt
Proof of what was decided, when, and why. Tamper-evident.
Auditability
Searchable, versioned, transparent. For you and your auditors.
Receipts & Audit Trails
Every decision emits a receipt. Every receipt is searchable, exportable, and auditable.
| Receipt ID | Unique identifier (e.g., rcpt_7f3k9x2m) |
| Decision | Yes / Conditional / No |
| Confidence Tier | Low / Medium / High |
| Reason Category | Non-sensitive explanation |
| Timestamp | UTC, ISO 8601 format |
| Flow ID | Which flow triggered this decision |
| Policy ID + Version | Which policy was applied |
| Signals Used | Categories only (not raw PII) |
| Override Log | If human intervention occurred |
| Audit Hash | Tamper-evident integrity check |
Policy Engine
Policies are versioned, testable, and rollback-ready. No surprises.
Versioning
Every policy change creates a new version. Full history preserved. Receipts reference exact version used.
Rollback
One-click rollback to any previous version. New bad policy? Undo in seconds.
Change Logs
Who changed what, when, and why. Auditors love this.
Sandbox Mode
Test policy changes against real traffic without affecting production decisions.
Data Handling
We minimize data by default. Retention is configurable. You control what stays.
| Data Type | Default Retention | Configurable? |
|---|---|---|
| Decision receipts | 90 days | Yes |
| Signal categories | 90 days | Yes |
| Raw input data | Not stored | N/A |
| Policy versions | Indefinite | Limited |
| Override logs | 1 year | Yes |
Human Review & Overrides
Conditional decisions route to your review queue. Overrides are logged and produce their own receipts.
Conditional Routing
- Conditional decisions enter review queue
- Configurable escalation rules
- SLA tracking on review time
Override Requirements
- Reason required (dropdown + notes)
- Override produces its own receipt
- Full audit trail preserved
Abuse Controls
Controls to prevent abuse and protect system integrity.
Rate Limiting
Configurable per-flow, per-user, and global limits. Prevent enumeration attacks.
Repeated Actor Controls
Detect and flag repeat offenders across sessions and identities.
Monitoring & Alerting
Real-time monitoring. Configurable alerts for unusual patterns.
Bot Detection
Identify automated attempts to bypass verification.
AI Governance
How our models work, what they don't do, and how you control them.
- Classification of document types and authenticity signals
- Anomaly detection for unusual patterns
- Risk scoring based on configurable thresholds
- Signal aggregation into decision categories
- No raw PII exposed in receipts
- No biometric claims unless explicitly enabled
- No autonomous decisions without policy constraints
- No training on your data without consent
| Metric | Description | Threshold | Current | Last checked |
|---|---|---|---|---|
false_positive_rate |
Legitimate requests incorrectly flagged | < 2% | 0.8% | Continuous |
false_negative_rate |
Risk events missed by the model | < 1% | 0.3% | Continuous |
model_drift_score |
Performance degradation over time | < 0.05 | 0.02 | 2026-01-20 |
latency_p99 |
Decision response time | < 500ms | 247ms | Real-time |
override_rate |
Human overrides of model decisions | < 5% | 1.2% | 2026-01-21 |
Reliability & Incidents
Trust means telling you when things aren't perfect.
Incident Process
- Detection + status page update
- Initial investigation
- Mitigation + communication
- Resolution + post-mortem
- Graceful fallback: You configure default allow/deny behavior
- Kill switch: You can bypass Werify entirely if needed
- Latency expectations: Decisions typically return in <100ms
Compliance Posture
We only list controls we have now. Roadmap items are labeled clearly.
- Data encryption at rest + in transit
- Role-based access controls
- Audit logging
- Data retention controls
- SOC 2 Type II In Progress
- ISO 27001 certification
- GDPR data processing addendum
- HIPAA BAA (healthcare customers)
- PCI DSS compliance
Artifacts Library
Downloadable artifacts for your security review and integration.
Download the Trust Pack
Forwardable to security and procurement - no call required.
Questions about our trust infrastructure?
Our security team is happy to walk you through the details.
Graceful fallbacks · Kill-switch · Configurable retention · View status