Security
How Veritas Source protects your data and maintains platform security.
HTTPS & Encryption
This Site is served exclusively over HTTPS with TLS 1.2+ encryption. All data transmitted between your device and our servers is encrypted in transit.
Your browser displays a padlock icon when connected securely. We recommend avoiding use on unsecured public WiFi networks.
Data Collection & Privacy
Veritas Source collects minimal personal data:
- —Contact Form Data: Name, email, and message content — used only to respond to your inquiry. Retained for 90 days.
- —Usage Analytics: Pages visited, time on page, clicks — anonymized and used to improve Site performance. Retained for 12 months.
- —Cookies & Tracking: First-party and third-party advertising cookies (Google AdSense). You can opt out via your browser settings or Google Ad Settings.
- —IP Address & Location: General geographic region (city/country level) from IP logs. Not linked to personally identifiable information.
What We Do NOT Collect
- —Passwords or login credentials (the Site does not require login)
- —Credit card numbers (payment processing is handled by Base44 Payments, a PCI-DSS compliant third-party provider)
- —Social security numbers or government IDs
- —Medical or health information
- —Biometric data
- —Detailed browsing history or session recordings
Third-Party Security
This Site relies on trusted third-party services. We are not responsible for their security practices:
- —Google AdSense: Serves advertisements. Review Google's Privacy Policy at https://policies.google.com/privacy
- —Base44 Payments: Processes subscription payments. PCI-DSS Level 1 compliant.
- —Analytics Services: Aggregate usage data without linking to personal identifiers.
Payment Security
Subscription payments are processed by Base44 Payments, a PCI-DSS Level 1 compliant payment processor. Credit card information is never stored on Veritas Source servers and is handled exclusively by Base44 Payments.
You are redirected to a secure checkout page hosted by Base44 Payments. Do not enter payment information on Veritas Source itself.
API & Backend Security
All backend functionality is protected by:
- —Authentication & authorization checks on user-specific operations
- —Rate limiting to prevent abuse and denial-of-service attacks
- —Input validation to prevent injection attacks and malformed requests
- —Secure handling of environment variables and API keys
- —Logging and monitoring of API requests for security analysis
User Roles & Access Control
The Site implements role-based access control:
- —Admin Role: Full access to add, edit, and delete news sources from the directory. Access restricted to authorized administrators only.
- —User Role: Public access to browse the directory and use analysis tools. No special privileges.
Users can only view and edit their own profile data. Administrators can manage user accounts and directory content.
Vulnerability Disclosure
If you discover a security vulnerability in Veritas Source, please report it responsibly. Do not publicly disclose the vulnerability. Instead, contact us with details of the issue.
We will investigate and respond to legitimate security reports promptly. We appreciate responsible disclosure and will acknowledge your contribution if you wish.
No Guarantee of Security
While we implement industry-standard security measures, no system is completely secure. We make no guarantee that:
- —The Site will be free from vulnerabilities or attacks
- —Your data will never be compromised or accessed by unauthorized parties
- —Third-party services will maintain their security standards indefinitely
- —Malware or phishing attempts will be prevented
Use the Site at your own risk. For sensitive transactions, use a secure device on a trusted network.
Data Breach Response
In the event of a confirmed data breach, we commit to:
- —Investigating the breach promptly and responsibly
- —Notifying affected users without unreasonable delay
- —Providing guidance on steps users can take to protect themselves
- —Cooperating with law enforcement if required
Security Policy Updates
This Security Policy may be updated from time to time to reflect new threats, technologies, or regulatory requirements. Changes will be posted on this page with an updated "Last updated" date. Your continued use of the Site constitutes acceptance of the updated policy.