Legal

Privacy Policy

How Verra handles your firm's data and protects your privacy.

Last modified: September 8, 2026

Lighthouse Software Technologies, Inc. dba Verra ("Verra", "we", "us", or "our") builds an institutional memory and agent platform for consulting firms. This Privacy Policy explains what data we collect, how we use it, and the choices you have. It covers the Verra platform, including workspace and Microsoft Office integrations, and this website at https://www.verra.com/ (together, the "Platform").

Verra is deployed for firms, not individuals. When your firm uses Verra, your firm is the controller of the engagement material, documents, messages, and other content it connects ("Firm Content"), and Verra processes that content on your firm's behalf and under its instructions. Where this policy says "you", it means you as a user of the Platform or a visitor to this website.

What data we access

Verra only accesses sources that your firm's administrators explicitly connect and scope. Access is granted through each provider's OAuth or enterprise app consent, uses read-only permissions wherever the provider supports them, and mirrors the permissions each user already holds in the source system.

Microsoft 365

SharePoint and OneDrive - documents, folders, and metadata from the libraries and sites your firm authorizes.

Outlook - email content, attachments, and metadata from mailboxes in scope, read-only.

Teams - channel messages and threads from channels your firm authorizes, read-only.

Word, Excel, PowerPoint, and Outlook add-ins - the contents of the file or message you are actively working in, so Verra can draft, cite, and edit alongside you.

Google Workspace

Drive - files and folders your firm selects, including content, names, and metadata.

Gmail - email content, subjects, and sender and recipient information, read-only.

Calendar - event details, participants, and scheduling information, read-only.

Other connected sources

Slack - channel messages and threads from channels your firm authorizes, read-only.

Box and Notion - files, pages, and folders your firm explicitly selects during configuration.

Salesforce - account, opportunity, and related records your firm authorizes, read-only.

Files uploaded directly - documents, decks, models, and other files a user uploads into a knowledge base or a run.

Data generated by using Verra

Prompts, questions, runbooks, and instructions you give to Verra and its agents.

Outputs Verra produces - drafts, decks, models, summaries, citations, and the intermediate work of an agent run.

Engagement memory and firm memory - facts, preferences, and precedents that your team reviews and chooses to retain.

Audit records - which user ran what, against which sources, under which policy version, and with what result.

Account and usage data - your name, work email, role, firm, authentication identifiers, and product usage and diagnostic logs.

How we use data

Knowledge and search

We parse, index, and embed connected content so that your firm can search across its full corpus, surface relevant prior engagements, and trace every figure back to its source. Entities such as people, organizations, dates, and figures are extracted to improve relevance and build an ontology for each corpus.

Agents and deliverables

Connected content and your instructions provide the context that agents use to plan and execute work - producing drafts, decks, models, and summaries in your firm's templates, with citations to the underlying sources. Retrieval is limited to material the requesting user is entitled to see.

Memory

Verra can retain engagement-level memory that builds run over run, and firm-level memory that is published only after review. Your team decides what is accepted into shared memory and what is rejected.

Governance and audit

We record each run with its policy version, inputs, and result hashes so that outputs are reproducible and auditable, and so that governance controls such as query filters, redaction, and output scanning can be enforced and validated.

Operating and improving the Platform

We use account and usage data to authenticate users, provide support, monitor reliability and security, and improve the product. Product improvement uses aggregated or de-identified usage data, never the substance of your Firm Content.

Where your data lives

Verra runs as a dedicated, single-tenant instance, deployed inside your firm's own cloud environment where that option is selected. Firm Content, indexes, embeddings, memory, and audit records stay isolated to your tenant and are never commingled with another firm's data. You choose the region and cloud in which data is resident.

All data is encrypted in transit using TLS and at rest, across storage and networks, with modern key management throughout. Independent third parties run regular penetration tests and vulnerability assessments against the Platform.

What we don't do

Train shared models on your Firm Content, for you or for anyone else. Engagement material stays isolated to your tenant.

Sell your data, or share it with other customers, organizations, or advertisers.

Access sources your firm has not connected, or surface content to a user who is not already entitled to see it.

Modify or delete your original files, emails, or messages in the source systems.

Retain OAuth tokens or credentials after a source is disconnected.

Data retention

Connected sources - indexed for as long as the source remains connected and in scope.

Disconnected sources - indexed content, embeddings, and tokens are removed within 30 days of disconnection.

Memory and audit records - retained according to the retention period your firm's administrators configure.

Firm offboarding - all Firm Content and derived data is permanently deleted within 30 days of termination, or returned on request before deletion.

Website data - demo requests and correspondence are retained for as long as needed to respond and follow up; analytics data is retained in aggregate.

Your firm's controls

Connect, scope, or disconnect any source at any time from the administration console.

Set retention periods and data residency for your tenant.

Decide who can run agents, which sources are in scope, and what each role is allowed to reach.

Review who has access at any time and revoke it in one step, with changes propagating to every agent immediately.

Review, accept, or reject anything before it enters shared memory.

Request export or deletion of your firm's data.

Your rights as an individual

Depending on where you live, you may have the right to access, correct, delete, or export personal data about you, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. If your personal data is contained in Firm Content, please contact your firm, which controls that data; we will support your firm in responding. For data we control, such as website and account data, contact us at hello@verra.com.

This website

When you request a demo, we collect the name, work email, company, role, team size, and message you provide, and use them to respond to your request. These details are delivered to us by email through a transactional email provider.

We use a product analytics service to understand how the website is used, including pages visited, approximate location derived from IP address, browser and device information, and errors encountered. This data is used to improve the site and is not combined with Firm Content.

Third-party services

We rely on a limited set of service providers to operate the Platform, such as cloud infrastructure, document processing, foundation model providers, and, for this website, email delivery and analytics. Each is bound by contract to process data only on our instructions, to maintain appropriate security, and, in the case of model providers, not to train on your data. We will provide a current list of subprocessors for your deployment on request, and will notify your firm before adding a new subprocessor that will handle Firm Content.

Compliance

Single-tenant isolation with encryption in transit and at rest.

OAuth 2.0 and enterprise app consent, with minimal, read-only permissions wherever supported.

Permission-aware retrieval that mirrors your existing access controls.

GDPR and applicable data protection laws, with a data processing agreement available for your firm.

Regular independent penetration testing and vulnerability assessment.

Changes to this policy

We may update this policy to reflect new features, integrations, or legal requirements. Material changes will be communicated to your firm's administrators by email before they take effect. The date at the top of this page reflects the most recent revision.

Contact

Questions about this policy or about how Verra handles data can be sent to hello@verra.com.

Questions? Contact us.