phoneveriflo
Pricing
Sign in Start free preflight
Home›Company›Security
Security

Security and data handling designed for sensitive contact data.

This page documents controls actually present in the application architecture and clearly separates them from infrastructure controls that still depend on the production deployment.

Read privacy policy Contact us
AES-GCM sensitive data encryptionPrivate object storageRBAC and audit trailWebhook signatures
Product principles
Explain what the signal means
Show price before processing
Keep result freshness visible
Zero upstream supplier leakage
Operational Playbook

Application-level controls implemented in the repository

The current codebase includes concrete security controls that can be documented after production configuration is verified.

1

AES-256-GCM encryption for sensitive application blobs using the configured data-encryption key.

2

Server-side object storage with private access; S3 uploads request AES256 server-side encryption when S3 mode is used.

3

Opaque session tokens stored as hashes.

4

API key digests rather than raw API keys in the database.

5

Role-based application access and admin audit records.

6

HMAC-derived cache identifiers so raw phone/email values are not used as cache keys.

7

Signed customer webhooks and destination checks.

Integration Architecture

Data minimization and retention

Uploads, cached results, and customer policies have explicit retention controls. The application clamps cache TTL to a maximum of 90 days; production retention should be set to the minimum period the business workflow requires.

What still requires production infrastructure

Repository controls are not the same as a complete security certification.

1

Production WAF/rate-limit strategy.

2

Managed secret storage and rotation.

3

Database encryption/backups and restore testing.

4

Egress/network policies.

5

Central monitoring, alerting, and incident response.

6

Independent security review and any formal compliance certification.

Security claims policy

Do not show SOC 2, ISO 27001, GDPR “certified”, penetration-test badges, uptime SLAs, or similar trust marks until there is actual evidence supporting the exact claim.

FAQ

Questions about security

Are phone numbers stored as plaintext cache keys?

No. The cache architecture derives HMAC identifiers from normalized input and stores encrypted result payloads.

Are API keys stored in plaintext?

The application uses digests for API-key lookup. Raw secret handling should be limited to key creation/display and the customer’s own secret store.

Does this page mean the company is SOC 2 certified?

No. Do not claim a certification until an independent, current report exists for the production organization and scope.

What should I do if I discover a security issue?

Use the production security reporting channel once it is configured and published; do not rely on an invented placeholder address.

Explore next

Related verification solutions

Explore related verification capabilities, documentation, and pricing.

PrivacyTermsStatusSupport
Next step

See the job composition before you commit.

Start with a free preflight scan. Review duplicate counts, syntax formatting, cache eligibility, and the frozen maximum quote in integer micros.

Start free preflight View pricing
phoneveriflo

Verification workflows with transparent preflight pricing, provider-neutral results, and visible freshness metadata.

Platform status

Products

Phone validationEmail validationNumber generatorBulk verificationDeveloper API

Solutions

CRM cleaningSMS list cleaningSignup verificationFraud preventionData migrationCustomer engagement

Developers

API documentationQuickstartLibraries & SDKsWebhooksChangelog

Resources

Blog & guidesToolsGlossaryCoverageSupport

Company

AboutSecurityPrivacyTermsContact
© 2026 phoneveriflo. All rights reserved.PrivacyTermsSecurityStatus