Security and Trust

Pay data deserves
real protection.

Pay is sensitive, so the way it is held matters as much as the way it is calculated. This is how Vareqa is built to protect your data, what we hold ourselves to today, and what we are still building.

Book a Pay Architecture ReviewSee our approach

The starting point

Less data, less risk.

Vareqa's core dataset is your job architecture: role titles, descriptions, grades, and bands. That is structured business data, not employee personal data. Pay equity and gap analysis use only the minimum information needed, aggregated wherever possible. Less personal data in the system means a smaller attack surface, lighter data-protection obligations, and, in many regions, no data-localisation trigger at all.

How your data is held

Six commitments, in plain terms.

The controls that sit behind the platform, stated plainly so your security and procurement teams can assess them.

Where your data lives

Vareqa runs on EU-hosted cloud infrastructure, so European personal data stays within the European Economic Area. A regional data-residency option is available for organisations with specific data-residency requirements.

Built around GDPR

Processing is designed around the GDPR principles of data minimisation and purpose limitation. A Data Processing Agreement and a current sub-processor list are available on request, and the platform supports the data-subject rights your employees are entitled to.

Access and audit

Role-based access controls govern who can see and change what. Every evaluation, override, pay band, and report is preserved in a complete, time-stamped history, the same audit trail that makes your pay decisions defensible. Data is encrypted in transit and at rest.

How AI is handled

AI assists the scoring; a qualified person always confirms it. The framework, not the model, governs the result, the system is model-agnostic, and your data is not used to train third-party models. Every AI suggestion is recorded alongside the human decision.

Retention and export

Your graded roles, rationale, bands, and outputs are exportable at any time, in open formats. If a subscription lapses, your data remains accessible read-only and exportable for at least 12 months before removal.

Responsible disclosure

If you believe you have found a security issue, write to security@vareqa.com and we will respond. We welcome responsible disclosure from security researchers and will work with you in good faith.

Honest about the gaps

What we are still building.

We would rather under-claim than overstate. Formal independent assurance, such as ISO 27001 certification and a SOC 2 report, is on our roadmap rather than in place today. Where a control is planned rather than live, we say so. If your procurement process has specific security requirements, raise them in a Pay Architecture Review and we will tell you exactly where we stand.

This page describes Vareqa's approach to security and data protection. It is provided for information and does not form part of any contract. The binding terms are set out in your agreement and Data Processing Agreement. Specifics such as hosting region, retention period, and certifications are confirmed in writing during onboarding.

Get Started

Book a Pay Architecture Review.

A 30-minute conversation. Tell us where your people work and where you are today, and we will walk you through which obligations apply to you, where your current exposure sits, and what it would take to put a defensible architecture in place on your timeline.

By requesting a review you agree to our Privacy Policy.

Prefer email? Write to info@vareqa.com