Security

Precise controls. No absolute promises.

Security supports the conversation; it does not make cloud translation invisible. This page distinguishes implemented safeguards from work that remains before a broader release.

Current as of August 22, 2026

Security model

The current Veridge beta is a private, invite-only browser messenger. Cloud services must process message content in plaintext for transcription, translation, and translated speech. For that reason, Veridge does not claim that the translated path is end-to-end encrypted, zero-knowledge, or free from risk.

Encryption

External application transport uses HTTPS/TLS. DynamoDB, S3, and SQS are configured for encryption at rest. Private S3 buckets block public access and reject insecure transport.

Authorization

The backend derives identity from authenticated server-side sessions and checks one-to-one conversation membership for messages, originals, media operations, playback URLs, deletion, and retries.

Sessions and browser protections

Browser sessions use server-side opaque cookies rather than localStorage tokens. Mutating requests require CSRF protection, and public-site cookies and application cookies remain separated by domain.

Media access

Uploads and downloads use short-lived, scoped operations after server authorization. Raw object keys are not treated as permission to access a message.

Provider access

The ElevenLabs key is retrieved server-side from a narrowly scoped AWS Secrets Manager secret. AWS runtime roles are separated by API and worker responsibilities and limited to the resources and provider-secret access required for their stage.

Abuse and cost controls

Authentication and message actions have rate limits. Paid provider work has a kill switch, queue backpressure, bounded concurrency, retry limits, and dead-letter alarms.

Processing boundaries

Speech recognition, translation, and speech synthesis receive the content required for their task. Provider requests use opaque request identifiers and avoid unrelated profile or conversation context. Voice notes are sent from private Veridge storage directly to the transcription provider without a second staging copy.

Logging and operational visibility

Application telemetry records content-free fields such as opaque request or message IDs, route, provider, model, stage, status, latency, byte or character count, retry class, and cleanup result. Message text, transcripts, translations, audio bytes, signed media URLs, access tokens, and provider response bodies are excluded by design.

Cloud access services may create their own operational metadata. Provider configuration and terms must be reviewed separately; Veridge does not treat a content-free application log as proof that every processor retains nothing.

Privileged access and auditability

Routine product behavior does not include an administrative conversation browser. Runtime permissions are separated and private content must not enter general support or operational tools. Stronger documented break-glass access controls, privileged-access auditing, production/non-production account separation, incident rehearsal, and public vulnerability intake remain pre-public-release work.

Retention and deletion

Message content and derived conversation artifacts have a 30-day user-visible lifetime unless deleted sooner. Account deletion starts in Settings, removes access on acceptance and permanently deletes every shared conversation for both participants. Pending cleanup is distinct from completion. Provider and backup retention limits are separate; see the Privacy Policy and account-deletion instructions.

Report a security concern

Veridge does not currently operate a public vulnerability-reward program. Do not open a public issue or send credentials, private messages, personal data, signed URLs, or exploit details through an ordinary form. Start a private, content-free report at support@veridge.io so an approved private channel can be arranged.