Security

Governance built for a shared AI ecosystem.

Vedra AI connects insurers to third-party AI models. Every model, dataset, and vendor in that chain introduces risk. Vedra Trust Bank is the governance framework that sets control expectations across the ecosystem, covering Vedra's own teams and every partner participating in a deployment.

The framework

Four pillars, one standard.

Vedra Trust Bank applies the same control expectations to Vedra, to partner models, and to the data moving between them. Insurers get common standards and transparent reporting instead of a separate diligence exercise per vendor.

Privacy by design

Data classification and tagging by sensitivity. Role-based access under least privilege. Encryption in transit and at rest. Anonymization and pseudonymization where third-party processing requires it. Retention and deletion aligned to contractual and legal obligation, with cross-border transfer controls.

Safe AI

Model documentation covering intended use and input and output specifications. Bias and fairness assessment during validation. Explainability tooling for interpreting decisions. Drift detection and performance monitoring in production. Risk tiering by regulatory exposure, business impact, and automation level.

Security as a priority

Zero-trust architecture with strict identity verification. Multi-factor authentication and secure key management. Regular penetration testing and vulnerability scanning. Documented incident response with defined roles and communication paths. Business continuity and disaster recovery testing. Log monitoring and threat detection.

Vendor management

Structured onboarding and due diligence covering model, security, and privacy assessment. Contracts carrying data protection, AI governance, and service level clauses. Ongoing monitoring of vendor certifications and control adherence. Defined offboarding with data recovery and deletion. Compliance attestation required for high-risk vendors.

Oversight

Accountability, not assertion.

The framework carries defined leadership roles for compliance, data protection, risk, and information security, with board oversight of the framework and its policies. Policies are version controlled and formally reviewed. Audit rights extend to third-party assessors.

Evidence and assurance
Third-party audit rights and a trust dashboard giving current risk and compliance health.
Policies and process
Documented policies for data use, AI adoption, vendor expectations, and security, on formal review cycles.
External alignment
Designed against GDPR, PIPEDA, Law 25, CCPA, ISO 27001, the NIST AI Risk Management Framework, and OSFI guidelines B10, B13, and E23.

Audited

Independently examined.

Security audited by a recognized third party organization. Penetration testing by a best in class security firm. Continuous monitoring of security posture.

Vulnerability disclosure

Report a vulnerability.

Suspected vulnerabilities in Vedra AI systems can be reported to security@vedra.ai. Reports are acknowledged and triaged under the documented incident response process.