Trust you can verify.
Not a badge in the footer. The compliance posture is engineered into the product, from the consent ledger to the audit trail. Here is exactly what that means.
A consent record you can prove.
Veft keeps an append-only, hash-chained ledger of consent: this person, at this time, approved this exact text. Any later edit breaks the chain, so the record is tamper-evident. A branded public microsite captures the approval; erasure can null the readable data while keeping the proof verifiable.
- Request, granted, and withdrawal — each a linked, timestamped event
- A branded public microsite for the candidate to approve
- Erasure nulls personal data without destroying the proof it once existed
AI you can defend, line by line.
Every text field carries its history: drafted by AI, edited by a human, written by a human, or approved. A re-run never overwrites text you've approved. Consultant-only processing remarks let the AI flag its own uncertainty before anything reaches a client.
- A draft → edited → approved trail on every field
- Approved text is never silently overwritten
- Processing remarks stay internal, never rendered to the client
Data discipline in the foundation.
Candidate data is hosted in the EU. Consent status sits on every contact, retention timers run automatically, and a soft-delete purge enforces the deletion clock. Stage transitions and field changes are fully audited — so the database is an asset, not exposure.
- EU data residency — data stays in Europe
- Consent status and retention timers on every contact
- A full audit trail on changes and stage transitions
On the right side of the AI Act.
Veft assists the consultant; it does not decide. The AI surfaces and organises information — it does not autonomously score, rank, or reject a candidate.
- The AI assists; the human decides
- No autonomous candidate scoring or rejection
- Transparency on what was AI-generated, on every field
Security you can trust.
Start with the foundations. Your data is encrypted, isolated from every other firm, and never used to train a model — yours or anyone else's.
- Your data is never used to train AI models
- Encrypted in transit and at rest
- Tenant isolation — never visible to another firm on Veft
- Hosted on Microsoft Azure, in the EU
- Security controls aligned to ISO 27001
Controls & verification.
When Veft collects consent and holds candidate data on your behalf, it stands in for part of your own GDPR duty — a responsibility that deserves more than taking our word for it. So we make it checkable.
- Export your full database whenever you want — your data stays yours
- Verify the consent record yourself — the hash-chain proves it, independent of us
- A tamper-evident trail a regulator can check too
Where your data lives, and who touches it.
Veft uses a small, named set of sub-processors — for enrichment, AI generation, email, and billing — each under a data processing agreement. The authoritative, current list lives in the DPA.
Read the DPAThe clearest way to judge the compliance story is to see the consent ledger and the provenance trail working. We'll show you in twenty minutes.