Trust and safety

Security Policy

The safeguards and shared responsibilities used to protect VeraSpace accounts, property content, payments and sensitive workflows.

Last updated: 8 September 2026

1. Our approach

VeraSpace uses layered administrative and technical safeguards proportionate to the information and service, including role-scoped access, authentication controls, private storage for restricted files, expiring file access where appropriate, audit records, backups and security monitoring.

2. Payment security

Sensitive gateway-payment credentials are handled by the payment provider and financial institutions. VeraSpace stores only the transaction and reconciliation information needed for the order and does not request payment passwords or one-time authentication codes.

3. Access control and data separation

Access is limited by role, organisation, team, agent–customer relationship, listing and assignment as applicable to the workflow. Raw conversations and customer profiles are not made available to unrelated organisations. Administrative access is restricted and logged according to operational need.

Operational contact and conversation data is separated from property-intelligence records. Analytics stores only approved dimensions and keyed pseudonymous identifiers where a stable count is necessary; it does not copy raw enquiry messages, identity documents or full payment credentials.

4. Your responsibilities

  • Use a unique password and do not share an account.
  • Verify the address before entering credentials or payment information.
  • Keep devices, browsers and email accounts updated and protected.
  • Do not upload unnecessary identity or financial information to listing fields or chat.
  • Report suspicious access, messages, payments or file links promptly.

5. No absolute guarantee

No internet service can guarantee perfect security. We assess risks, improve controls and respond to incidents, but users should also keep independent copies of important business records and use appropriate device security.

6. Reporting a security concern

Send a clear description, affected URL or account, approximate time and safe reproduction details to contact@veraspace.my or +60 19-944 9066. Do not access, copy, modify or disclose another person’s data while investigating. We welcome good-faith reports and will triage them according to risk.

7. Incident response

We investigate suspected incidents, contain and remediate confirmed issues, preserve appropriate records and notify affected persons or authorities where required by applicable law. Public statements are made only after facts and disclosure obligations are assessed.

8. Mobile devices, local drafts and permissions

The mobile app stores its session token in operating-system secure storage. Optional biometric unlock uses the device’s authentication service; VeraSpace does not receive your fingerprint or facial template. Device unlock is an additional local control and does not replace the server’s account permissions. Shared or compromised devices can expose an unlocked session or local drafts.

Website preferences, visitor identifiers and Brand Studio drafts may persist in your browser. Signing out of the server does not necessarily erase browser storage or photos you saved to the device. Clear relevant local data before transferring a device. Revoke an integration or report a lost device promptly; disabling a connection does not erase independently held provider data.

If translated versions conflict, the Bahasa Malaysia version applies to the extent permitted by law.