Security Policy
Protecting the information our customers and partners entrust to us is part of the same quality culture that governs how we manufacture medical devices. This policy describes the technical and organizational measures Vero Animal Health applies to keep your data, payments and accounts secure.
1. Scope and principles
This policy applies to all personal and business information collected through our website, contact and account forms, email, telephone orders and invoicing. Our security program follows three principles: confidentiality (only authorized people can access your data), integrity (data is accurate and cannot be altered without authorization) and availability (systems and information are accessible when needed). It complements our Privacy Policy, which explains what we collect and why.
2. Website security
- Encryption in transit. All pages and forms on veroanimalhealth.ca are served over HTTPS (TLS 1.2 or higher). Data you submit is encrypted between your browser and our servers.
- Hardened static architecture. The website is delivered as static files from a content-delivery network, which eliminates the database and plugin vulnerabilities common to content-management systems.
- Security headers. We apply Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options and Referrer-Policy headers to protect against injection, click-jacking and downgrade attacks.
- Forms. Contact, newsletter and dealer-application forms include anti-spam protection and are transmitted through a secure, SOC 2-compliant form-processing service before reaching our team at info@veroanimalhealth.ca.
- Monitoring. Availability and certificate validity are monitored continuously, and dependencies are reviewed and updated on a regular schedule.
3. Payment security
Vero Animal Health does not store complete credit-card numbers on its systems. Card payments are processed by PCI DSS-compliant payment providers; we receive only a confirmation and, where applicable, the last four digits of the card. Trade accounts are invoiced and paid by electronic funds transfer, cheque or card through our accounting provider. Never send card details by email — our staff will not request them that way.
4. Data protection and access control
- Customer records are stored in access-controlled business systems hosted in Canada or in jurisdictions with comparable privacy protection, protected by encryption at rest and multi-factor authentication.
- Access is granted on a need-to-know basis, reviewed periodically and revoked immediately when an employee's role changes or ends.
- All employees who have access to or are involved in processing personal information are bound by a confidentiality clause and receive security-awareness training.
- Backups are performed regularly, encrypted and tested so that records can be restored after an incident.
- Personal information is retained only as long as needed for the purposes described in our Privacy Policy and applicable tax and regulatory obligations, then securely deleted.
5. Email and communications
Legitimate messages from Vero Animal Health are sent from addresses ending in @veroanimalhealth.ca. Our domain is protected by SPF, DKIM and DMARC so that forged messages are rejected or flagged by recipient mail systems. We will never ask you to confirm passwords, full card numbers or banking details by email or text. If you receive a suspicious message claiming to be from us, do not click any links — forward it to info@veroanimalhealth.ca.
6. Customer accounts
Trade accounts are approved manually after verification of business registration or veterinary licence. You are responsible for keeping login credentials confidential and for all activity under your account. Choose a unique, strong password, do not share it, and notify us immediately if you believe your account has been accessed without authorization. We may suspend accounts showing signs of compromise.
7. Incident response
We maintain an incident-response procedure covering detection, containment, investigation, remediation and notification. If a security incident results in a real risk of significant harm to individuals, we will notify affected customers and the Office of the Privacy Commissioner of Canada as required by PIPEDA, without unreasonable delay, and explain the steps being taken.
8. Reporting a vulnerability
We welcome reports from security researchers and customers. If you discover a vulnerability in our website or systems, please email info@veroanimalhealth.ca with the subject "Security report", including the affected URL, steps to reproduce and your contact details. We ask that you do not access or modify data that is not yours, and that you give us a reasonable time to remediate before public disclosure. We acknowledge reports within two business days and will not pursue legal action against good-faith research conducted in accordance with these guidelines.
9. Physical and product security
Our facility in Mississauga, Ontario is access-controlled and monitored. Product traceability is maintained by lot number from manufacturing through shipment, so that in the event of a quality issue or recall we can identify and contact every affected customer quickly.
10. Changes to this policy
We review this policy at least annually and whenever our systems change materially. The current version is always published on this page with its revision date.
11. Contact
Vero Animal Health — Security & Privacy
4 Robert Speck Parkway #500, Mississauga, Ontario L4Z 1S1, Canada
Tel: 289-813-0159 · Email: info@veroanimalhealth.ca