Security and Trust
Pay is sensitive, so the way it is held matters as much as the way it is calculated. This is how Vareqa is built to protect your data, what we hold ourselves to today, and what we are still building.
The starting point
Vareqa's core dataset is your job architecture: role titles, descriptions, grades, and bands. That is structured business data, not employee personal data. Pay equity and gap analysis use only the minimum information needed, aggregated wherever possible. Less personal data in the system means a smaller attack surface, lighter data-protection obligations, and, in many regions, no data-localisation trigger at all.
How your data is held
The controls that sit behind the platform, stated plainly so your security and procurement teams can assess them.
Vareqa runs on EU-hosted cloud infrastructure, so European personal data stays within the European Economic Area. A regional data-residency option is available for organisations with specific data-residency requirements.
Processing is designed around the GDPR principles of data minimisation and purpose limitation. A Data Processing Agreement and a current sub-processor list are available on request, and the platform supports the data-subject rights your employees are entitled to.
Role-based access controls govern who can see and change what. Every evaluation, override, pay band, and report is preserved in a complete, time-stamped history, the same audit trail that makes your pay decisions defensible. Data is encrypted in transit and at rest.
AI assists the scoring; a qualified person always confirms it. The framework, not the model, governs the result, the system is model-agnostic, and your data is not used to train third-party models. Every AI suggestion is recorded alongside the human decision.
Your graded roles, rationale, bands, and outputs are exportable at any time, in open formats. If a subscription lapses, your data remains accessible read-only and exportable for at least 12 months before removal.
If you believe you have found a security issue, write to security@vareqa.com and we will respond. We welcome responsible disclosure from security researchers and will work with you in good faith.
Honest about the gaps
We would rather under-claim than overstate. Formal independent assurance, such as ISO 27001 certification and a SOC 2 report, is on our roadmap rather than in place today. Where a control is planned rather than live, we say so. If your procurement process has specific security requirements, raise them in a Pay Architecture Review and we will tell you exactly where we stand.
Get Started
A 30-minute conversation. Tell us where your people work and where you are today, and we will walk you through which obligations apply to you, where your current exposure sits, and what it would take to put a defensible architecture in place on your timeline.