versa
Last updated March 26, 2026

Security Measures

Important: The German version of this document is legally binding under Austrian law, irrespective of the reader's jurisdiction (Versa Training GmbH is an Austrian company). This English version is an informational translation provided for convenience only. EU consumer protections of your country of residence apply regardless of this binding-language clause (Rome I Regulation, Art. 6(2)). In case of conflict between the German and English texts, the German text governs.

German version

This document describes the technical and organisational measures (TOMs) implemented by Versa Training GmbH to protect the personal data processed via the Versa Platform.

Versa implements the measures described below. The infrastructure providers and sub-processors used to do so are listed at app.versa.training/legal/subprocessors.


Pseudonymisation and Encryption

MeasureDescription
Encryption in transitTLS 1.3 for all data in transit
Encryption at restAES-256 encryption for all stored data
Key managementDatabase encryption keys are managed by the infrastructure provider. API keys for AI providers are stored with restricted access (authorised personnel only). Service role keys are rotated upon infrastructure changes.
PseudonymisationApplied to data used for AI quality improvement; direct identifiers are stored separately from pseudonymised records

Confidentiality

MeasureDescription
Access controlRole-Based Access Control (RBAC) on the principle of least privilege; access is reviewed quarterly
AuthenticationGraduated access controls for administrative access; SSO/SAML support for customer organisations
Data separationRow Level Security (RLS) on all database tables; per-organisation data separation via workspace-based policies with SECURITY DEFINER helper functions
Network securityWAF and DDoS mitigation at the deployment layer; HTTPS enforced on all endpoints
Endpoint securityProduction database access restricted to the service role; direct database access limited to authorised personnel with audit logging
Personnel securityAll employees, agents, and contractors are bound by documented confidentiality obligations pursuant to § 6 of the Austrian Data Protection Act (DSG); the obligation survives termination of the employment or contractual relationship
Security trainingMandatory data protection and security awareness training for all persons with access to personal data; training at onboarding and annually thereafter
Physical securityDelegated to the cloud infrastructure providers; data centres in use are ISO 27001-certified.

Integrity

MeasureDescription
Change managementAll code changes are subject to peer review and staged deployment
Development securitySecurity requirements are addressed in the design phase; automated static analysis in the CI/CD pipeline
Audit loggingSystem event logging and user activity audit logs; logs are protected against tampering
Monitoring and alertingAutomated monitoring of system health and security events; alerts on anomalous activity
Input validationValidation of all data inputs at application level

Availability and Resilience

MeasureDescription
Backup and recoveryDaily automated backups, retained for 30 days; recovery procedures tested at least annually; RPO target: 24 hours; RTO target: 4 hours
Business continuityDocumented disaster recovery procedures; reviewed and tested annually
InfrastructureEU-hosted cloud infrastructure with built-in redundancy

Testing and Evaluation

MeasureDescription
Vulnerability managementAutomated dependency scanning; security patches applied within 30 days (critical: 7 days)
Security assessmentsAnnual security review of the platform and infrastructure; penetration testing by qualified third parties at least annually
Incident responseDocumented incident response procedures with severity classification, escalation paths, and post-incident review; tested at least annually
Sub-processor assessmentSub-processors are selected on the basis of their security posture; preference is given to providers with ISO 27001 or SOC 2 Type 2 certification

Data Protection by Design and by Default

MeasureDescription
Data minimisationOnly the data necessary to provide the service are collected
Retention managementData lifecycle management in accordance with agreed retention periods; deletion is ensured through automated processes and manual review
Privacy defaultsNew features default to the minimum necessary data processing; additional processing requires explicit activation

Questions? Contact privacy@versa.training