Verisight Help Center Support ticket Open portal

Your data

What Verisight stores, what it never sees, and how you can export or delete it.

What we store

  • Assessment data: scope, authorisations and your scan-declaration acceptances, evidence, findings, reports and their history.
  • Connector state: which Microsoft 365 tenant or AWS role is connected, and the permissions granted. Microsoft and AWS credentials are used only by the collection service and are never shown in the portal.
  • Software inventory: the package list, file name and checksum of each lockfile you upload. The file itself is not kept.
  • Account data: your name, email, username, profile photo, and your organizations and roles.
  • An audit trail of security-relevant actions: logins, authorisations, evidence downloads, key changes and deletions.

What we never see

  • Your password. Sign-in is handled by the Sentinel identity service. See Profile, password and two-factor authentication.
  • Your card details. Payments are processed by Stripe.
  • The contents of your AWS objects. Even the extended profile can list resource names, but never read S3 object contents.
  • Private package names. Packages from private registries, git or local paths are never sent to any advisory service.

Evidence integrity

Evidence is stored unaltered, with when and how it was collected. PDF reports are versioned and never overwritten, and executive briefs are saved as unchangeable snapshots. What you were shown can always be reproduced.

Export and deletion

Owners can download a complete export of their account and every organization they solely own, then delete everything. See Export your data and delete your account.