.ai

Security & Trust

Security practices

Your security program contains sensitive information. We treat it that way.

Understand how vCISO.ai protects customer data, separates workspaces, uses AI providers, and keeps material decisions under human control.

Workspace protection

Current product boundaries

Organization-scoped access
Encrypted connector credentials
Private evidence storage
Human approval for material decisions
Customer content is not used to train AI models. AI drafts and recommends; authorized people approve.

Security principles

Boundaries are part of the product.

vCISO.ai handles program records that may be sensitive. Authentication, tenant scope, data minimization, and human approval are enforced in the application rather than left to marketing promises.

Review released read-only integrations

Least privilege

People and integrations receive only the access needed for an authorized task.

Tenant isolation

Protected reads, mutations, downloads, and relationships stay scoped to the authorized organization.

Encrypted handling

HTTPS protects data in transit, managed services encrypt stored data, and connector credentials are encrypted before storage.

Read-only integrations

Available connectors collect supported observations and do not change customer systems.

AI with boundaries

Customer content is not used to train AI models, and AI cannot approve its own conclusions.

Human approval

Authorized people approve policies, evidence, exceptions, and risk decisions.

Data flow and architecture

Customer context moves through explicit boundaries.

This customer-level view explains the systems involved without exposing credentials, internal hostnames, or sensitive infrastructure detail.

Authentication and tenant isolation

Clerk handles sign-in, sessions, and organization membership. Protected product reads and mutations also resolve local organization, user, membership, and role state near the requested data. UI visibility alone never grants access.

Encryption and secrets

HTTPS protects browser traffic. Managed database and private object-storage services encrypt stored data. Connector credentials are encrypted before storage, and OAuth state is short-lived, signed, and bound to the organization and provider.

AI data handling

Content is sent to the AI provider only when an authorized product task requests generation. Context is minimized to the task. Customer content is not used to train AI models. AI cannot approve evidence, make risk decisions, change external systems, or issue an audit result.

Retention, export, and deletion

Customers own submitted content and generated work product. Supported exports are available in the product, and deletion can be requested after cancellation subject to the short wind-down and legal exceptions described in the current Terms and Privacy Policy. No exact backup-deletion interval is promised.

Operational security

The application uses role-aware authorization, audit history for real state changes, rate limiting, monitored errors, dependency review, secure development checks, and managed infrastructure. Error monitoring is scrubbed to retain safe categories and limited diagnostic tags rather than customer content.

Service providers

Subprocessors and their purpose

These providers support the released product. Their role does not imply that vCISO.ai holds the provider's certifications.

vCISO.ai subprocessors, purpose, and high-level data category
ProviderPurposeHigh-level data
VercelApplication hosting and private object storageApplication traffic and stored customer artifacts
NeonManaged Postgres databaseOrganization-scoped application records
ClerkAuthentication and organization membershipIdentity, session, and membership information
AnthropicOptional AI generationMinimized context for an authorized AI request
StripeSubscription billing and payment processingBilling account and payment information
ResendTransactional emailRecipient and message delivery information
UpstashRate limiting and public lead persistenceRate-limit keys and submitted lead fields
SentryApplication error monitoringMinimized error category and safe diagnostic tags

Documents and requests

Review the current commitments.

Review the commitments published today or contact our security team with a specific request.

Terms of Service

Service, customer responsibility, AI review, and outcome boundaries.

Open Terms of Service

Vulnerability disclosure

Report the affected route, integration, or component and reproduction steps. Do not include credentials, access customer data, perform destructive testing, or degrade availability. No response-time commitment is stated.

Open Vulnerability disclosure

Start with the roadmap

Start with a readiness roadmap built around real security work.

Tell vCISO.ai about your company and target audit, then see the first control your team should complete.