Privacy Policy.
How Verlane, a product of Adria Software LLC, collects, uses, protects, and retains the information you entrust to us.
Effective June 25, 2026 · Last updated June 25, 2026
Who we are
Verlane is an AI-run email- and account-security product for carriers, brokers, and 3PLs, owned and operated by Adria Software LLC ("Adria," "we," "us"). This policy explains what information we process when you visit our website, request a posture report or demo, or use the Verlane console, and the choices you have. It applies to the Verlane website and application; it does not cover third-party sites we link to.
Information we collect
- Account & contact information — name, work email, company, role, and the credentials you set, when you are invited to the console, claim a posture report, or contact us for a demo.
- Posture & assessment inputs — the self-reported answers you provide to generate a security-posture report or cyber-insurance questionnaire.
- Connected-environment telemetry — once you connect Google Workspace or Microsoft 365, we process sign-in, message-metadata, and mailbox-rule signals, plus any carrier/load data you provide, strictly to detect fraud and account takeover. We request the minimum scopes needed and never read mail content for any purpose beyond detection.
- Usage & technical data — standard log data (IP address, browser, timestamps, request identifiers) generated when you use the service, used to operate, secure, and debug it.
How we use information
We use the information above to provide and operate the service — detecting fraud, correlating incidents, producing posture reports and questionnaires, and notifying the people you designate. We also use it to secure the service against abuse, to communicate with you about your account and inquiries, and to meet our legal obligations. Verlane detects, investigates, and drafts response actions; a human approver must approve any action against your environment before it runs. We do not sell your data, and we do not use your connected-environment telemetry to train general-purpose AI models.
Data minimization
Authoritative incident detail is stored tenant-scoped and is accessible only behind login and role-based access control. External notifications (email and, later, Slack/SMS) carry only a headline, a plain-English summary, and a link back to the app — never raw internals such as IP addresses, email addresses, or message payloads. Secrets and OAuth tokens are held in encrypted configuration, never in our source code.
How we share information
We share information only with service providers who help us run Verlane — cloud hosting, transactional email, error monitoring, and the AI provider that writes incident and posture narratives — each bound by contract to process data solely on our instructions. We may also disclose information when required by law or to protect the rights, safety, and security of our users, the public, or Adria. If Adria is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction, subject to this policy.
Retention
We keep account and customer data for as long as your account is active and as needed to provide the service, then for a reasonable period to meet legal, accounting, and security obligations. Lead and provisional ("prospect") data captured from the public posture flow is automatically purged after a retention window if it is never converted into an account. You may request deletion of your data as described below.
Security
We protect data in transit and at rest, enforce least-privilege tenant isolation, hash credentials, store secrets in encrypted configuration, and require a human approval gate before any response action touches your environment. No method of transmission or storage is perfectly secure, but security is the core of what we build, and we apply the same discipline to our own product.
Your choices and rights
You may access, correct, export, or delete your personal information, object to or restrict certain processing, and disconnect a provider at any time. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA/CPRA; we honor those rights and do not discriminate against you for exercising them. To make a request, contact us using the details below. Because Verlane is a workplace tool, some requests may need to be routed through the organization that administers your account.
Marketing inquiries
When you request a posture report or a demo, we capture your contact details in our own systems to follow up. We use no third-party form services. You can opt out of marketing communications at any time, and we will still send essential service and security messages.
International data & children
Verlane is operated from the United States; if you use it from elsewhere, your information is processed in the U.S. under appropriate safeguards. Verlane is a business product not directed to children, and we do not knowingly collect information from anyone under 18.
Changes to this policy
We may update this policy as the product and the law evolve. When we make material changes, we will revise the "Last updated" date above and, where appropriate, notify you. Your continued use of Verlane after an update means you accept the revised policy.
Contact us
Questions about this policy or your data? Reach Adria Software LLC at privacy@verlane.ai, or get in touch here.