Security and privacy
Last updated: July 18, 2026
Verbasil holds your company's memory: your decisions, your conversations, your learnings. That is sensitive material. This page explains what we do with it, what we do not do with it, and what we have not built yet.
Where your data lives
Our server-side processing runs in our host's Paris region. Our database, which holds your memory, is hosted in the European Union. Our usage analytics are processed in Europe.
The public pages of our website are delivered through a global content network, like almost every website. This involves none of your data: that network only serves pages that are identical for every visitor.
We rely on a small number of providers, each for a specific role: hosting, database, email delivery, AI model processing, analytics, error monitoring, and connections to your tools. They are named individually, with each one's role, in our privacy policy.
We never sell your data. We share it with no one other than these providers, and only to operate the service.
Your data is isolated from everyone else's
Isolation between organizations is not handled by application code. It is enforced by the database itself. In practice, even in the event of an application bug, a query cannot return another organization's data: the database engine refuses it.
This isolation is covered by an automated test suite, which verifies among other things that one user cannot reach another user's data. We run it before deployments that touch the data model.
Files you import are stored in a private space that is never publicly accessible. Every access goes through a temporary link generated on demand.
What the AI models see
Verbasil uses AI models to read your content and extract decisions, learnings and signals from it. We use Anthropic, OpenAI and Google for this.
Your data is not used to train these models.We use these providers' business offerings, whose terms exclude training on data submitted through their programming interface.
On our side, we keep technical statistics about these calls, volume, duration and cost, to manage our spending. The content of your data is not part of them.
We protect your memory against malicious content
A product that reads your documents and emails can be targeted by instructions hidden inside that content, designed to hijack the AI or make it reveal what it knows.
We filter this risk in two places: on the way in, on everything imported or typed, and on the way out, before a response reaches you. Detected attempts are blocked and produce no action on your memory.
What we do not collect
Our analytics tools never receive your email address, only an anonymous identifier. Our error monitoring tool is configured to strip request content and cookies before anything is recorded: when an error occurs, we see its nature, not your data.
Our detailed product analytics only start after your explicit consent. Before that, only a cookieless, identifier-free visit count takes place: nothing is stored on your device and nothing allows us to recognize you from one visit to the next. See our cookie policy.
Connections to your tools
When you connect an external tool, the access authorizations are held by our specialized provider, not by Verbasil. We do not store your login credentials.
The access keys you generate to connect Verbasil to your AI assistant are never kept in readable form on our side. If you lose a key, we cannot give it back to you, you have to generate a new one. That is deliberate.
Your rights, and how to exercise them
- Delete your account: from your settings, without writing to us. Deletion is real and permanent: your account, your organizations and all associated memory are erased in a single operation. We ask you to type a confirmation phrase, because it cannot be undone.
- Archive without destroying: a decision or experiment that is no longer current can be archived. It leaves your working view but stays in your history. A company memory is a ledger: we prefer to expire rather than delete.
- Stop receiving our emails: an unsubscribe link is included in every non-essential email.
- Access or retrieve your data: write to contact@verbasil.com, we handle the request manually within 30 days. Self-service export is in progress.
What we have not built yet
We would rather say it than let you guess.
- No security certification. No SOC 2, no ISO 27001. These audits cost tens of thousands of euros and take months of work. Verbasil is a young product built without outside funding: that money goes to the product today. If your organization requires a certification, tell us, it will weigh on our priorities.
- No two-factor authentication yet. Sign-in works through an email link or a Google account, with no password to remember or to leak.
- Encryption at rest is the one provided by our hosts. Your data is encrypted on disk by our database host, and encrypted in transit. We do not add an application-level encryption layer on top, which means your content remains readable to administrators holding legitimate database access. This is how nearly every online service works, but we would rather you knew.
- Automated data export does not exist yet. It is done on request, by hand.
This section will change over time. If it empties out while nothing else on this page changes, be suspicious.
Reporting a problem
If you believe you have found a vulnerability, write to contact@verbasil.com. Verbasil is built by one person: we do not run a bounty program, and we will not promise a response time we could not keep. We read everything, and we handle security reports ahead of everything else.