Security & data

Trust starts with managed access and traceable actions.

Verdant applies technical and organisational controls across different parts of the experience: account governance, user roles, action history and public-site protections. This page describes controls visible in the deployed environment without claiming an external security certification.

Access governance

Responsibilities can be separated according to the user’s role.

Verdant structures profiles so operations, supervision, finance, drivers, audit and customers do not necessarily use the same functions.

01

Distinct roles

Application permissions are organised by profile so users can be limited to functions relevant to the work they need to perform.

02

Account approval

The registration process includes management approval before profiles requiring approval become fully operational.

03

Contact verification

Email and phone verification workflows are integrated for profiles that need to confirm their contact details.

Application traceability

Attributed actions help explain what actually happened.

The Verdant environment retains operating events and includes a logging mechanism used across different workflows. This supports a more reviewable history of operational and system activity.

Important: a technical audit trail does not replace governance. Organisations remain responsible for account allocation, offboarding and their own internal procedures.
Access

Identified users

Internal functions rely on authenticated accounts.

Action

Recorded events

Operational and selected system events feed histories and logs.

Supervision

Separated responsibilities

Roles distinguish field execution, supervision and administrative functions.

Public website

A deliberately lightweight and restrictive web surface.

The Verdant public website is served over HTTPS and uses browser security policies that limit permitted resources and behaviours.

TransportHTTPS & HSTS

The public domain enforces encrypted transport and sends a Strict-Transport-Security policy.

BrowserContent Security Policy

Scripts, styles, images and fonts are restricted to explicitly permitted sources.

IsolationFrame protection

Deployed headers prevent the public site from being embedded in an unauthorised frame.

PrivacyRestricted permissions

The marketing site does not request browser access to camera, microphone or geolocation.

ResourcesSelf-hosted fonts

Site fonts are served from the same domain to reduce external dependencies.

FormsValidation & anti-spam

The demo request uses browser and server validation, request throttling and a honeypot field.

Limits & continuous improvement

Security is a process, not a badge.

This page describes currently deployed controls and is not an attestation of compliance with a particular standard. Contractual, privacy, retention or integration requirements should be reviewed in the context of each customer deployment.

For institutional review: use the demo request to specify your governance, access, integration or data-handling requirements so they can be considered before deployment.

Do you have specific security or governance requirements?

Share them with the Verdant team so they can be discussed alongside the operational scope of your project.