데이터 처리 및 보안 정책Data & Security Policy
시행일: 2026-06-22 · 최종 수정일: 2026-08-26 Effective date: 2026-06-22 · Last updated: 2026-08-26
주식회사 베리티(이하 “회사”)는 회계법인·감사인을 위한 감사 워크플로우 소프트웨어(AuditMind)를 제공하며, 고객 데이터를 보호하기 위해 권한 기반의 관리적·기술적·물리적 보호조치를 시행합니다. 본 정책에 기재된 구성은 배포 환경 및 고객과의 계약에 따라 달라질 수 있습니다. Verity Co., Ltd., a corporation organized under the laws of the Republic of Korea (the “Company”), provides audit workflow software (AuditMind) for audit firms and auditors and implements permission-based administrative, technical and physical safeguards to protect customer data. The configurations described here may vary according to the deployment environment and the contract with the customer.
1. 접근통제 및 테넌트 격리1. Access Control and Tenant Isolation
권한 기반 접근통제와 테넌트 격리 정책을 통해 다른 조직(회계법인) 및 권한 없는 사용자의 데이터 접근을 제한합니다. 같은 법인 내에서도 Engagement 단위로 접근 권한을 분리합니다.Permission-based access control and tenant isolation restrict data access by other organizations (audit firms) and unauthorized users. Within the same firm, access is separated at the engagement level.
2. 암호화2. Encryption
전송 구간의 모든 통신은 TLS 1.2 이상으로 암호화되며 HTTPS가 강제 적용됩니다. 저장 데이터는 AES-256 방식으로 암호화되어 보관되며, 데이터베이스는 관리형 PostgreSQL의 저장 암호화를, 감사증거 및 조서 파일은 오브젝트 스토리지의 서버측 암호화(SSE)를 적용합니다.All communications in transit are encrypted using TLS 1.2 or higher, and HTTPS is enforced. Data at rest is stored encrypted with AES-256: the managed PostgreSQL database applies storage-level encryption, and audit evidence and workpaper files are protected by server-side encryption (SSE) in object storage.
파일은 공개 URL로 제공되지 않습니다. 권한 검증을 통과한 사용자에게만 통상 5~15분간 유효한 단기 서명 URL을 발급하거나, 애플리케이션 서버가 직접 스트리밍하는 방식으로 제공합니다. 외부 검토자에게 제공되는 조서 파일은 서명 URL을 발급하지 않고 애플리케이션이 직접 스트리밍하며 워터마크가 적용됩니다.Files are never served from public URLs. Access is granted either through short-lived signed URLs, typically valid for 5 to 15 minutes and issued only after permission checks, or by streaming through the application server. Workpaper files made available to external reviewers are streamed by the application without signed URLs and are watermarked.
애플리케이션은 브라우저 수준의 보호조치로 X-Frame-Options, frame-ancestors 콘텐츠 보안 정책(CSP), X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy 헤더를 적용합니다.The application applies browser-level protections including X-Frame-Options, a frame-ancestors Content Security Policy, X-Content-Type-Options: nosniff, Referrer-Policy and Permissions-Policy headers.
3. 백업3. Backups
데이터베이스는 관리형 인프라에서 일 1회 자동 백업되며, 백업은 7일 이상 보관됩니다. 보관기간은 계약 플랜에 따라 확대됩니다. 오브젝트 스토리지에 저장된 감사증거 및 조서 파일은 버전관리를 통해 삭제 및 덮어쓰기로부터 보호됩니다.The database is automatically backed up once daily on managed infrastructure, and backups are retained for at least 7 days. Retention is extended according to the contracted plan. Audit evidence and workpaper files in object storage are protected against deletion and overwriting through versioning.
초 단위 복구 지점을 요구하는 Point-in-Time Recovery 및 보관기간 확대는 엔터프라이즈 계약 시 제공 가능합니다. 복구 절차 및 목표 복구 시점은 계약 및 운영 기준에 따릅니다.Point-in-Time Recovery with second-level granularity and extended retention are available under enterprise agreements. Recovery procedures and recovery point objectives follow the contract and operational standards.
4. 로깅 및 Audit Trail4. Logging and Audit Trail
자료 업로드, AI 분석, 검토·수정·승인 등 주요 활동 이력을 감사 이벤트 기록에 남겨 내부 품질관리와 점검 대응을 지원합니다. 각 이벤트에는 행위자, 역할, 대상 엔티티, 시각이 기록되며, 기록 시점에 SHA-256 해시가 생성되어 사후 변조를 탐지할 수 있습니다. 데이터베이스 권한 정책상 감사 이벤트는 생성과 조회만 허용되고 수정은 허용되지 않습니다.Key activity history — uploads, AI analysis, review, edits and approvals — is recorded in an audit event log to support internal quality control and inspection readiness. Each event records the actor, role, target entity and timestamp, and a SHA-256 hash is generated at the time of recording so that subsequent tampering can be detected. Database access policies permit only the insertion and retrieval of audit events; modification is not permitted.
로그는 계약·법령·고객의 보존정책에 따라 보관되며, 보존기간이 경과한 후 삭제됩니다.Logs are retained per contract, law and the client's retention policy, and are deleted once the retention period has elapsed.
5. 보안사고 통지 절차5. Incident Notification
회사는 개인정보 또는 고객 데이터와 관련한 침해사고를 인지한 경우 부당한 지연 없이 영향을 받는 고객에게 통지합니다. 통지에는 인지한 범위에서 사고의 성격, 영향을 받은 데이터의 유형과 범위, 회사가 취한 조치 및 고객에 대한 권고 조치를 포함합니다.Upon becoming aware of a breach involving personal information or customer data, the Company will notify affected customers without undue delay. The notification will include, to the extent known, the nature of the incident, the categories and scope of data affected, the measures taken by the Company and the actions recommended to the customer.
개인정보보호법이 적용되는 경우 회사는 정보주체에게 지체 없이 통지하고 개인정보보호위원회 및 한국인터넷진흥원에 법정 기한 내 신고합니다. GDPR 등 고객에게 72시간 통지 의무가 적용되는 경우, 회사는 고객이 해당 기한을 준수할 수 있도록 필요한 정보를 제공합니다.Where the Korean Personal Information Protection Act applies, the Company will notify data subjects without delay and report to the Personal Information Protection Commission and the Korea Internet & Security Agency within the statutory deadline. Where the customer is subject to a 72-hour notification obligation under laws such as the GDPR, the Company will provide the information necessary for the customer to meet that deadline.
회사는 사고 조사, 영향 완화 및 재발 방지 조치를 수행하고 그 결과를 고객에게 공유합니다.The Company will investigate the incident, mitigate its impact, implement measures to prevent recurrence, and share the results with the customer.
6. 보존 및 삭제6. Retention and Deletion
고객 데이터는 해당 주문서, 고객 계약, 고객의 적법한 지시 또는 적용되는 전문기준 및 감독규정에서 정한 기간 동안 보존됩니다.Customer Data is retained for the period specified in the applicable Order Form, customer agreement, the customer's lawful instructions or applicable professional and regulatory requirements.
한국 외부감사 업무의 경우, 관련 한국 법령에서 요구하는 범위에서 관련 감사조서를 8년간 보관할 수 있습니다. 미국 업무를 포함한 다른 국가의 업무는 고객 계약 및 배포 구성에서 보존기간을 정합니다.For Korean statutory-audit engagements, relevant audit workpapers may be retained for eight years where required by applicable Korean law. For engagements in other jurisdictions, including U.S. engagements, the applicable retention period is defined in the customer agreement and deployment configuration.
시스템 접속기록 및 보안 로그는 원칙적으로 1년간 보관합니다. 업로드·AI 분석·검토·수정·승인 이력을 포함한 Engagement Audit Trail은 해당 고객 계약 또는 보존정책에서 정한 기간 동안 보관합니다.System access and security logs are generally retained for one year. Engagement audit trails, including upload, AI analysis, review, edit and approval history, are retained for the period specified in the applicable customer agreement or retention policy.
소송, 규제기관 조사 또는 그 밖의 Legal Hold 사유가 있는 경우, 필요한 기간 동안 삭제를 보류할 수 있습니다. 계약 종료 시 고객은 적용 법령, 전문적 의무 및 합의된 보존정책이 허용하는 범위에서 고객 데이터의 내보내기 또는 삭제를 요청할 수 있습니다. 보존기간이 경과한 데이터는 관련 데이터베이스 레코드 및 오브젝트 스토리지 파일을 포함하여 정해진 삭제 절차에 따라 삭제됩니다.Where litigation, a regulatory investigation or another legal-hold event is pending, deletion may be suspended for the required period. Upon termination, the customer may request export or deletion of Customer Data, subject to applicable law, professional obligations and the agreed retention policy. Expired data is deleted through defined deletion procedures, including deletion of the associated database records and object-storage files.
7. 하위 처리자 (서브프로세서)7. Subprocessors
회사는 서비스 제공을 위해 클라우드 인프라 및 AI 처리 등 하위 처리자를 이용할 수 있습니다. 하위 처리자 목록 및 변경 사항은 고객에게 안내하며, 계약상 요구되는 보호조치를 적용합니다.The Company may use subprocessors such as cloud infrastructure and AI processing to provide the Service. The list of subprocessors and any changes are communicated to customers, and contractually required safeguards are applied.
- 클라우드 인프라: Amazon Web Services(대한민국 서울, ap-northeast-2), Supabase(대한민국 서울, ap-northeast-2), Vercel(서버 함수: 대한민국 서울, icn1 / CDN: 글로벌 네트워크)Cloud infrastructure: Amazon Web Services (Seoul, Republic of Korea, ap-northeast-2), Supabase (Seoul, Republic of Korea, ap-northeast-2), Vercel (server functions: Seoul, Republic of Korea, icn1 / CDN: global network)
- AI 처리: Microsoft Azure OpenAI(대한민국 Korea Central), OpenAI API(글로벌 처리 환경), Anthropic Claude API(글로벌 처리 환경)AI processing: Microsoft Azure OpenAI (Korea Central, Republic of Korea), OpenAI API (global processing environment), Anthropic Claude API (global processing environment)
- 업무용 이메일·알림: Google Workspace(미국)Business email and notifications: Google Workspace (United States)
- 트랜잭션 이메일 및 인증 발송: Plus Five Five, Inc. (Resend) — 미국Transactional email and authentication delivery: Plus Five Five, Inc. (Resend) — United States
8. 문의8. Contact
보안 및 데이터 처리 관련 문의: info@verityaudits.comSecurity and data-processing inquiries: info@verityaudits.com