Procurement
A supplier you can put through procurement
Built for public-sector and enterprise buyers: documented governance, secure delivery, and full source ownership.
Company profile
Verity Digital is an independent software engineering practice delivering secure, production-grade web platforms for SMEs, public-sector bodies and enterprise buyers. Engagements are delivered to documented standards, with security and data protection designed in from the first commit.
- Structure
- Sole trader (independent consultant)
- Principal
- Miroslav Tadej
- Based in
- Ireland
- Engagement model
- Fixed-scope or retained
- Delivery
- Owned source code, deployed to your infrastructure
- Contact
- info@veritydigital.ie
Standards & assurance
Aligned to recognised standards today — formal certifications shown honestly as roadmap.
Aligned to
- OWASP — Application-security practices aligned to the OWASP Top 10
- GDPR — Data-protection-by-design; documented GDPR position
- Secure SDLC — Security reviews and validation built into delivery
- Parameterized data access — No string-built SQL, anywhere
Certification roadmap
These formal certifications are not yet held — listed transparently as targets, available to discuss for a given engagement.
- ISO/IEC 27001Roadmap
- Cyber EssentialsRoadmap
Governance documents
Download our governance pack — the framework overview and the six supporting policies.
Governance Framework Overview
The lead document: how the governance framework fits together and indexes the six policies below.
PDF · 70 KB
Information Security Policy
How information assets are protected across the engagement lifecycle.
PDF · 113 KB
Data Protection Policy
Handling, retention, minimisation and subject-rights procedures.
PDF · 108 KB
GDPR Compliance Statement
Our data-protection-by-design position and lawful processing approach.
PDF · 82 KB
Secure Development Policy
Secure SDLC controls — review, validation, dependencies, secrets.
PDF · 101 KB
Business Continuity & DR Plan
Backup, recovery and continuity approach for delivered systems.
PDF · 101 KB
Quality Management Statement
Delivery standards, quality gates and acceptance criteria.
PDF · 92 KB
Data processing terms. Where we handle personal data on your behalf, GDPR Article 28 requires a written processor agreement. Ours — including the sub-processor list, EU data residency and the technical and organisational measures — is available on request, and we work to a contracting authority’s own GDPR directions where one applies. Ask for a copy.
Delivery methodology
Six phases, quality gates between each, governance controls applied throughout.
Capability statements
Secure web application delivery
Full-stack PERN platforms with httpOnly-cookie JWT auth, role-based access control and hardened HTTP headers.
Data protection & GDPR
Lawful-basis mapping, data minimisation, subject-rights handling and a documented data-protection position.
Payments & financial integrity
Stripe integration with webhook signature verification; money stored and computed as integer cents — never floats.
Cloud & containerised deployment
Dockerised builds with reproducible environments, targeting AWS or your own infrastructure.
API design & integration
Versioned REST APIs with consistent contracts, Zod-validated inputs and integration with third-party systems.
Documentation & handover
Architecture decisions recorded as they are made, with full source ownership and a clean handover.
Tender enquiry
Submit an RFP / tender enquiry
Send your requirement and request our governance documents. Logged and tagged for procurement follow-up.