Security
Your transcript, and what we do with it
What happens to a transcript you submit
When you paste a transcript or upload a file, the text is processed on our server, sent to an AI model provider to identify your strongest moments and generate your outputs, then stored in our database against your account so you can open and edit the project again. That is the whole journey.
Everything travels over TLS 1.2 or better and is stored encrypted at rest by our database provider. It is never posted anywhere public, never shared with another customer, and never sent to any third party other than the model provider producing your outputs.
Model providers, and training
Verso routes across providers depending on the task. The How the AI works page shows which model handles which step in the current deployment.
We use these providers under their business API terms, which prohibit training on API traffic. We do not fine-tune any model on customer transcripts, we do not use your content to improve prompts without asking, and we do not sell or license customer text to anyone for any purpose.
Who at Verso can read your content
Access to the production database is limited to the engineers who operate it, and that access is used to fix things, not to browse. We do not read customer transcripts for product research.
If you open a support ticket about a specific project and send us the link, we may open that project to answer your question. If you would rather we did not, say so in the ticket and we will work from your description instead.
Data location
All data Verso holds on your behalf is stored in the United States. Our database, file storage and hosting infrastructure run in US regions. We do not transfer customer content to servers outside the US.
How long we keep it
- Projects and the transcripts stored with them: until you delete them, or until 30 days after you delete your account, whichever is sooner.
- Voice style samples: until you delete them from Settings, or until account deletion.
- Account records: for as long as the account is open, then 30 days.
- Form submissions from contact and support forms: 24 months.
- Server logs, which record request paths and timings but not transcript content: 30 days.
- Backups: rolling 7 days, after which deleted data is gone from backups too.
Deleting your data
Delete any project from your dashboard, which removes the transcript and all generated outputs. Delete your whole account from Settings, which removes every project, voice sample and account record.
Both are immediate and neither needs a support ticket. If you want written confirmation for your own records, email us and we will send it. The full explanation of export and deletion options is on the your data page.
Accounts and access
- Passwords are hashed with scrypt and a per-user salt. We never store or log a password, and nobody at Verso can read one.
- Sessions are httpOnly, sameSite cookies signed with a server-side secret, and they expire after 30 days.
- Google sign-in is supported so you do not have to keep another password at all.
- Every request for a project checks that the project belongs to the account asking for it, in the database query itself rather than only in the page.
Our own posture
- Two-factor authentication is required on every service Verso uses, with no exceptions and no shared logins.
- Production database access is limited and reviewed quarterly.
- Dependencies are updated on a weekly cadence and security advisories are acted on within 72 hours for anything reachable from production.
- We do not yet hold a SOC 2 report. We are a Pre-Seed company and would rather tell you that than imply otherwise. Certifications are on the roadmap. If you need a completed security questionnaire for procurement, email us and we will fill it in honestly.
Reporting a vulnerability
Email security@tryverso.tech. We acknowledge within two business days, we will not threaten you for reporting in good faith, and we will tell you when it is fixed. If you want to be credited, say so and we will.
This page describes what Verso does today. The privacy policy is the legal version of the same thing, and the your data page explains the export and deletion controls. Last reviewed August 1, 2025.