VerseauVERSEAU
SECURITY & TRUST

Your numbers,
guarded.

How Verseau protects your data — every line on this page is true of production as it runs today, or it is not here.

HOW VERSEAU PROTECTS YOUR DATA
Hosting
The application runs on Railway (US-West). All traffic is served over HTTPS, on TLS 1.2 or newer. The marketing site runs on Vercel. Those are the only two places Verseau is hosted.
One bar, one wall
Every record in Verseau carries the organization it belongs to, enforced on the server — the browser can never ask for another bar's data. Automated cross-tenant isolation tests run on every code change, and an independent adversarial review (2026-08-29) confirmed org A cannot read or write org B's integrations, audit log, roles, team, or settings.
Access control
Permissions are role-based and split by side of house (bar vs. kitchen); seeing costs is its own separate grant, so line staff can count without seeing margins. All enforcement is server-side, and a manager cannot hand out permissions they don't themselves hold.
Credentials you give us
Credentials you give us (POS, distributor logins) are encrypted at rest with AES-256-GCM under a key held only in the running environment, bound to your organization so a copied blob can't be read anywhere else. They are never shown again after you enter them, never returned by any API, and erased the moment you disconnect the integration.
Your data
We request read-only access and no guest or employee data. We never sell your data and never use it to train models. Invoices read by AI are treated as untrusted input and are reviewed before they change anything, unless you explicitly opt a specific sender into auto-approval — and even then, only a message that passes provider authentication from that exact verified sender address is trusted.
Logging
Our logs record request metadata only — method, path, status, timing — and never request or response bodies, secrets, or tokens. Verified live against production.
Backups
We take consistent, off-host database backups using SQLite's online-backup API (no downtime), verify each with an integrity check, and store them in private, encrypted-at-rest cloud storage separate from the server. Our restore procedure is documented and runs automatically as part of our test suite on every build. We do not yet run automated daily volume snapshots; off-host backups are taken on a manual/scheduled cadence.
Audit trail
Every change to a cost, count, role, credential, or invoice approval is recorded with who did it and when, in an append-only log that cannot be edited or deleted through the application.
Vulnerability handling
Reach us at aidan@zefren.com. We acknowledge reports within two business days and fix critical issues before the next deploy. Our CI blocks a deploy on failing tests or a known high-severity dependency vulnerability, and dependencies are audited on every build and updated weekly.
Incident response
If something goes wrong we contain it, assess the scope per affected bar, notify affected customers within 72 hours with what happened and what to do, and write a post-mortem. Where personal information is involved, we follow Michigan Identity Theft Protection Act notice obligations; a bar's cost book is not personal information, but we would notify you anyway.
Data export & deletion
You can request a full export of your data at any time. On account closure we delete your data within 30 days.
What we don't claim
We do not have SOC 2, ISO 27001, or a third-party penetration test yet. When we do, this page will say so — and not before.

Questions about any of this? Write to aidan@zefren.com.

START TRACKING YOUR LIQUID PROGRESS
VERSEAU

A bar operations platform built by beverage people, for beverage people. Liquid Progress, from bottle to glass.

© {{ year }} Verseau. All rights reserved.

LIQUID PROGRESS