Security

We hold ourselves to the bar we help you reach

vCISO.AI runs its own security program on vCISO.AI. Here is how we protect your data, in plain language.

Encryption everywhere

TLS for every connection in transit. Encryption at rest for the database and file storage.

Strong authentication

Sign in is handled by a dedicated identity provider with MFA support. Sessions are short lived and revocable.

Tenant isolation

Every record is scoped to your organization and every query is checked against your membership. No shared buckets, no cross tenant reads.

Least privilege

Production access is limited to the people who operate the service, with audit trails on administrative actions.

Hardened infrastructure

We build on managed platforms with strong security track records instead of running our own servers.

AI with boundaries

AI features only see the data needed for the task, scoped to your organization. Your data is not used to train models.

Subprocessors

The services that touch your data, and why.

VercelApplication hosting and file storage
NeonPostgres database
ClerkAuthentication and organization management
AnthropicAI generation
ResendTransactional email
UpstashNewsletter lead storage

Found something?

We welcome good faith security research. Report vulnerabilities to security@vciso.ai and we will respond quickly, credit you if you want it, and never take legal action against good faith research.

Trust is the product.

See how we help you build the same kind of program for your customers.