Email and consent
A work email, exact policy versions, optional marketing choice, and minimum request metadata are processed.
SECURITY AND DATA BOUNDARY / REV 2026.07
MINIMUM PUBLIC DATA / FAIL-CLOSED ACCESS
Public intake verifies possession of an email address and records a service interest. It is not a customer-data portal, identity-proofing service, or confidential workspace.
Email verification reduces automated abuse and confirms inbox possession. It does not verify a person's legal identity, authority, employment, or entitlement to transmit customer information.
PUBLIC ACCESS FLOW
EMAIL → CODE → SCOPEWHAT HAPPENS
Public intake is intentionally narrow. A visitor can inspect services and request a scope discussion, but cannot upload customer artifacts.
A work email, exact policy versions, optional marketing choice, and minimum request metadata are processed.
A production request requires a valid Turnstile token checked server-side for the expected action and hostname.
A six-digit code expires after ten minutes. Attempts and resends are bounded; response language resists account enumeration.
A successful check creates a random, HttpOnly, Secure, SameSite session cookie. The service stores only a keyed token value.
COLLECTION INVENTORY
PUBLIC INTAKE ONLYDATA MINIMIZATION
PUBLIC CONTROL SET
DEFENSE IN DEPTHIMPLEMENTED DESIGN
Controls reduce risk; they do not create an absolute security guarantee. Production activation remains fail-closed when required configuration or approved policy versions are absent.
Production traffic is intended to terminate at Cloudflare with HTTP redirected only after an active edge certificate is verified. HSTS is staged after HTTPS validation.
Content Security Policy, frame denial, no-sniff, restrictive permissions, no-referrer, and same-origin isolation headers reduce browser attack surface.
Email ciphertext is separated from keyed lookup values. Verification codes and sessions are not stored in directly reusable form.
Global, IP-derived, and email-derived application limits supplement Cloudflare edge and Turnstile controls.
JSON bodies, fields, lengths, values, methods, origins, and content types are bounded. Unknown fields and invalid states fail closed.
A verified visitor can request deletion of the public access, consent, and active session records, subject to applicable contractual or legal retention.
PUBLIC SERVICE PROVIDERS
LIMITED FUNCTIONSCURRENT PUBLIC STACK
The current privacy notice and applicable signed agreement control provider use. Public-provider configuration is reviewed as part of production operations.
DNS, HTTPS, static delivery, abuse controls, serverless request handling, and the minimum access database.
Produces a short-lived token that the application validates with the expected action and hostname.
Delivers the requested one-time code from a verified Verahelm sending domain.
PRIVATE ENGAGEMENT DATA
SEPARATE AGREEMENT REQUIREDBEFORE RECEIPT
Public verification does not create confidentiality or authorize transfer. A signed scope identifies the accepted data classes, purpose, access route, owners, subprocessors, retention, return, deletion, incident duties, and intellectual-property treatment.
Customer confirms ownership or authority for every submitted material.
Data is minimized to fields required by the evaluation contract.
Credentials and recovery material remain outside ordinary transfer packages.
Regulated, personal, export-controlled, or high-consequence information requires explicit written acceptance.
Return, retention, and deletion are confirmed at engagement closure.
SECURITY QUESTIONS
PUBLIC INTAKEPLAIN-LANGUAGE ANSWERS
A recovery phrase would create a new secret for customers to safeguard and a support or custody burden for Verahelm. Public access uses short-lived inbox verification; stronger returning-customer authentication can use passkeys in a separately designed workspace.
No. It demonstrates inbox possession only. Authority, identity, confidentiality, and data rights are established separately before work or private transfer.
Not through public intake. The verified workstation presents service information and a scoping route. Any file transfer requires an approved private engagement channel.
No organization can promise absolute security. Verahelm describes implemented controls, limits collection, fails closed when critical configuration is missing, and states contractual duties in the applicable agreement.
Privacy requests may be sent to [email protected]. General security concerns may be sent to [email protected] without including exploit payloads, credentials, customer data, or confidential attachments.
VERAHELM HOLDINGS LLC / PUBLIC DATA BOUNDARY