SECURITY

Security is the first product requirement.

Veritas Ask is developed in the European Union for professional and institutional work. This page distinguishes implemented controls from capabilities that require formal deployment validation.

DEVELOPED IN THE EUROPEAN UNION

European by design. Security before convenience.

Veritas Ask is developed by MAŃSKI AI s.r.o. in the European Union. Security, confidentiality and user control are treated as core product requirements — not optional features.

Designed for institutions that carry public responsibility.

Governments and public authorities
Hospitals and healthcare institutions
Prosecutors, courts and legal teams
Universities and regulated organisations

SECURITY FIRST

Implemented controls

Server-side identity and access checks
Private document storage and deletion controls
User- and Matter-scoped data access with audit metadata
Traceable sources, uncertainty and model routing

Institutional deployment requires formal technical, legal and procurement validation for the intended data and use case.

MAŃSKI AI s.r.o. • European Union

Encryption

TLS protects data in transit. Hosted storage uses provider-managed encryption at rest.

Identity and access

Protected routes validate identity and organisation membership server-side. Owner, administrator, member and viewer permissions are enforced at each data boundary.

Data separation

Personal and organisation records use separate scopes. Organisation documents, projects, conversations and reports require current tenant membership.

File controls

Uploads are size-limited and content-checked. Organisation files carry a classification, a personal-data declaration and explicit approval before AI processing.

Secret management

AI and payment credentials are read only on the server from protected runtime configuration.

Data location

European deployment and data-residency requirements must be contractually confirmed for each institutional configuration before sensitive data is introduced.

Sensitive data guard

Documents declared sensitive are blocked by default. Controlled processing requires an organisation-recorded security review and administrator approval. Classification is declared by users, not automatically guaranteed.

Human authority

Generated professional outputs remain pending until a human reviewer approves or rejects them. AI output is never represented as an official decision.

Retention and export

Organisation owners can preview retention impact, permanently remove expired content and export governed records without exposing private storage keys.

Audit trail

Security-relevant organisation activity is recorded with actor, target, time and cryptographic event hashes for integrity evidence.

Institutional deployment boundary

Before processing classified, patient, criminal-case or other highly sensitive information, the institution must complete its security review, DPIA where applicable, procurement and contractual validation, retention configuration and verification of infrastructure location. SSO/SAML, SCIM, independent penetration testing, formal certifications and contractual data-residency commitments are not claimed by this product interface and remain controlled deployment requirements.