Distinct roles
Application permissions are organised by profile so users can be limited to functions relevant to the work they need to perform.
Verdant applies technical and organisational controls across different parts of the experience: account governance, user roles, action history and public-site protections. This page describes controls visible in the deployed environment without claiming an external security certification.
Verdant structures profiles so operations, supervision, finance, drivers, audit and customers do not necessarily use the same functions.
Application permissions are organised by profile so users can be limited to functions relevant to the work they need to perform.
The registration process includes management approval before profiles requiring approval become fully operational.
Email and phone verification workflows are integrated for profiles that need to confirm their contact details.
The Verdant environment retains operating events and includes a logging mechanism used across different workflows. This supports a more reviewable history of operational and system activity.
Internal functions rely on authenticated accounts.
Operational and selected system events feed histories and logs.
Roles distinguish field execution, supervision and administrative functions.
The Verdant public website is served over HTTPS and uses browser security policies that limit permitted resources and behaviours.
The public domain enforces encrypted transport and sends a Strict-Transport-Security policy.
Scripts, styles, images and fonts are restricted to explicitly permitted sources.
Deployed headers prevent the public site from being embedded in an unauthorised frame.
The marketing site does not request browser access to camera, microphone or geolocation.
Site fonts are served from the same domain to reduce external dependencies.
The demo request uses browser and server validation, request throttling and a honeypot field.
This page describes currently deployed controls and is not an attestation of compliance with a particular standard. Contractual, privacy, retention or integration requirements should be reviewed in the context of each customer deployment.
Share them with the Verdant team so they can be discussed alongside the operational scope of your project.