Security
Last updated: 10 July 2026
Packaging-compliance data — lab certificates, declarations of conformity, artwork, supplier documents — is sensitive, and much of it is your legal record. This page describes, plainly, how we protect it. We’d rather tell you what we actually do than claim badges we don’t hold.
Where your data lives
Application data — the database and uploaded files — is hosted with Supabase in the European Union (Paris). Our application’s server functions run in the EU region too, so your data doesn’t make an unnecessary transatlantic trip. The main exception is AI processing, described below.
Encryption
Your data is encrypted in transit (TLS) and at rest.
Tenant isolation
Every workspace’s data is isolated at the database level using row-level security, so one customer’s data is never reachable from another customer’s session.
Authentication
Passwords are stored only as salted hashes, never in plain text. We enforce a minimum length and check new passwords against known-breached-password lists to block credential reuse. Sessions use secure cookies; we set no advertising or cross-site tracking cookies inside the signed-in product.
Your data and AI
When you use an AI-assisted feature (artwork verification, recyclability scoring, certificate extraction, document drafting), the content for that feature is processed by Anthropic’s Claude API to produce the result. We do not permit our AI providers to train models on your data, and we run no third-party advertising or analytics trackers anywhere in the signed-in product. Our public marketing pages use consent-gated Google Ads conversion measurement only; see our Privacy Policy for details.
Access control
Access to production systems is limited to the people who need it, on a least-privilege basis.
Backups and recovery
The database is backed up daily, and we have tested restoring from backup.
Sub-processors
We rely on a small set of vetted providers, each under a data-processing agreement — the current list is in our Privacy Policy.
Deleting your data
You can delete your account and its workspace at any time from settings. We remove it from production systems within 30 days — including signed declarations of conformity — with residual copies in encrypted backups expiring on their normal cycle. Regulatory retention duties (such as the PPWR’s 5–10 year duty to keep declarations) rest with your organisation, so export or print any records you must keep before deleting; the product reminds you at the point of deletion.
If something goes wrong
If a personal-data breach affecting you occurs, we notify you and, where required, the relevant supervisory authority without undue delay, as the GDPR requires.
Certifications and compliance
We process personal data under the GDPR, with EU data residency and real, self-serve deletion. We do notcurrently hold formal certifications such as SOC 2 or ISO 27001, and we won’t claim ones we don’t have; if a formal audit becomes necessary for your organisation, talk to us. A Data Processing Agreement (GDPR Article 28) is available on request.
Reporting a vulnerability
If you believe you’ve found a security issue, please email contact@verdlynx.com with the details. We welcome responsible disclosure and will acknowledge your report.