Security Policy
The security of our customers' and end buyers' data is a priority for Verify Solutions, S.L.
1. Technical and organizational measures
- TLS 1.2+ in transit and AES-256 at rest.
- Multi-factor authentication (MFA) for staff with access to sensitive systems.
- Role-based access control and least-privilege principle.
- Environment segregation (production, staging, development).
- Audit logs and continuous monitoring.
- Periodic backups and disaster recovery plan.
- Regular dependency review and security patching.
2. Responsible vulnerability disclosure
If you detect a vulnerability, please report it responsibly:
- Email security@ecomverify.email with a detailed description.
- Allow reasonable time to fix before public disclosure (minimum 90 days).
- Do not exploit the vulnerability beyond what is strictly necessary.
- Do not access, modify or disclose third-party data.
We commit to acknowledge receipt within 72 hours, maintain transparent communication and credit you if you wish.
3. Incident notification
In case of a personal data security incident we will notify AEPD and affected parties when applicable under Arts. 33 and 34 GDPR. Incidents affecting data obtained via Amazon SP-API will additionally be reported to Amazon within 24 hours.
Last updated: 2026-08-03. Verify Solutions, S.L. — Tax ID B27661099 · Girona Companies Register (Registro Mercantil), Sheet GI-79107 — Carrer Riera Garrap, 37, 17007 Girona, Spain.