Veristria

Legal

Privacy Policy

The short version: we collect an email address if you give us one, and each product collects what it needs to do the job you asked it to do. Nothing is sold, nothing is shared with advertisers, and there is no tracking across sites.

Last updated 24 August 2026


Who we are

The controller of the personal data described here is Veristria, a Norwegian aksjeselskap (AS) under incorporation (24 August 2026), based in Norway. The organization number will be published on this page the day registration completes.

One address reaches us for anything on this page — access requests, deletion requests, corrections, or a question about a sentence you do not believe: info@useveristria.com.


Scope

What this page covers

Four sites, one company, four different answers to “what do you actually collect?”

This page covers veristria.com and gives the accurate summary for each product. Each product site — keydrift.dev, rowshield.dev and feeguard.dev — publishes its own privacy page with the full detail for that service, and that page is the authoritative one if you are a customer of it.


What veristria.com collects

This site has no accounts, no login, no payments and no analytics. There is exactly one form on it: the launch list.

When you submit that form we store three things — the email address you typed, lowercased; a tag saying which of our sites captured it; and the time of the insert. No IP address, no browser fingerprint, no referrer, no name. The address is never written to a log, on success or on failure. We use it once: to tell you when the products go live, and to send the newsletter if you asked for it. Every message we send carries an unsubscribe link.

The rest of this site is static pages. It sets no cookies of its own and loads no third-party scripts.


Per product

What the products collect

These differ more than you might expect. One of the three never asks for a credential at all.

KeyDrift — reads what your site already serves in public

You give KeyDrift a URL. It fetches that page and the JavaScript files the page links to, exactly as a browser would, and reads them for exposed keys. It never asks for a credential, never signs in to anything, and issues only GET and HEAD requests — the fetch layer refuses anything else.

It stores the URL you submitted, the URL it ended up at after redirects, which files it read, and the findings. A finding never contains a live secret: the value is masked to a short prefix and suffix, and stored alongside a salted hash. Scan reports created from a URL are public and can be opened by anyone with the link. If you paste source code instead of a URL, the pasted text is not stored at all and the report is not indexed.

Full policy on keydrift.dev

RowShield — reads your database's structure, not its contents

The free audit takes a URL and, optionally, the publishable key your app already ships to browsers. It checks which tables that key can reach. To do that it asks each table for a single row, then immediately reduces the answer to the column names and the row count. Row values are never stored, never returned to you, and never leave the request.

Continuous monitoring uses a Postgres connection string you create and can revoke. It is encrypted before storage and decrypted only inside the scanner. The scanner runs a fixed set of catalog queries — tables, columns, policies, indexes, storage bucket settings, server version — and issues no writes of any kind. What we keep is a snapshot of that structure plus the findings derived from it.

Full policy on rowshield.dev

FeeGuard — reads your Stripe account through a key you restrict

The free audit deliberately does not accept a Stripe key. You paste event data, or run the built-in sample, and nothing you paste is stored — the findings are returned to your browser and the export is built there.

Monitoring uses a Stripe API key you create yourself. FeeGuard asks for a restricted key with five read permissions; two write permissions are optional and only enable automatic recovery. The key is encrypted with a per-tenant key before it is written, is never returned to your browser, and stops working the moment you revoke it in Stripe. What we store from your account is the reconciliation record: Stripe object identifiers, amounts, and the discrepancies found between them.

Full policy on feeguard.dev


Accounts, support and payments

Accounts. The product sites sign you in with a magic link or an email and password handled by our authentication provider. We hold your email address, an account identifier, and which organization you belong to. We do not store passwords ourselves.

Support conversations. Where a site offers the support assistant, the conversation is processed by a third-party model provider and logged on our side so a human can pick up what the assistant could not answer. If you give a name and an email so we can send you the transcript, that is stored with the conversation. The assistant is labeled as an AI and will say so if you ask.

Payments. Subscriptions are billed through Stripe. Stripe collects and holds the card details; we never see or store a card number. What reaches us is the customer and subscription identifier, the plan, and whether the invoice was paid.


Legal bases

Why we are allowed to hold it

Contract
Account data, scan and audit records, and billing data are processed because you asked for the service and we cannot deliver it otherwise.
Consent
The launch list and the newsletter. You gave us the address for that purpose, and you can withdraw it from any message we send, or by emailing us.
Legitimate interests
Keeping the services up and abuse under control — rate-limit counters, server logs, and the audit trail of who changed what inside an account. We keep these narrow and short-lived.
Legal obligation
Invoices and the accounting records behind them, which Norwegian law requires us to retain.

Processors

Who else touches it

These are the companies that process data on our behalf. We do not sell data and we have no advertising partners.
Vercel
Hosting and delivery for all four sites. Sees requests as they arrive.
Supabase
The Postgres database and the authentication service behind the products and the launch list.
Stripe
Payments, subscriptions and the billing portal. Stripe is the controller of the card data it collects.
OpenRouter
Model inference for the support assistant. It receives the conversation text only — no account records, no scan data.

Individual products use a small number of additional processors for things like queues and transactional email. Each product’s own privacy page lists them.


Cookies

We set strictly necessary cookies only. On the product sites that means the session cookie that keeps you signed in, and the cookies Stripe sets during checkout. There are no advertising cookies, no analytics cookies and nothing that follows you to another site. veristria.com sets none at all.

That is why you are not reading this through a consent banner. Strictly necessary cookies do not require consent, and we have nothing else to ask you about. If that ever changes — if we ship anything that is not strictly necessary — a consent banner appears first, and it will default to off.


How long we keep it

Launch-list and newsletter addresses: until you unsubscribe or ask us to delete them.

Account and product data: for as long as the account exists. Close the account, or email us, and we delete it.

Scan and audit records: kept with the account that created them. Records created without an account — a free scan you ran while logged out — are currently kept until you ask us to remove them. We would rather tell you that plainly than publish a retention period we do not yet enforce in code.

Invoices and accounting records: for the period Norwegian bookkeeping law requires, which is longer than any of the above and is not something we can shorten on request.

Rate-limit counters: minutes to a day, then gone.


Your rights

Under the GDPR you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable form, object to processing based on legitimate interests, and ask us to restrict processing while a dispute is open. Where processing rests on consent, you can withdraw it at any time.

Email info@useveristria.com and we will answer within a month. There is no form and no fee. We will ask you to confirm you control the address in question, because handing an account’s data to whoever asks first would be its own privacy failure.


Where the data lives

We are based in Norway and the services are operated for the EEA. Some of our processors are established in the United States and may process data there. Where that happens it is covered by the transfer mechanisms those providers publish — standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. Their current terms are linked in the processor list above.


Complaints

Tell us first if you can — most things are a misunderstanding we can fix the same day. If we do not resolve it, you have the right to complain to the Norwegian Data Protection Authority, Datatilsynet, at datatilsynet.no, or to the supervisory authority where you live.


Changes to this policy

When the code changes, this page changes, and the date at the top moves. If a change materially affects what we do with data you have already given us, we will say so by email rather than quietly editing the page.

Ask us anything on this page

Including “prove it”. If a sentence here does not match what a product does, that is a bug and we want to know.