Security

We hold ourselves to the bar we help you reach

vCISO.ai is designed around the same security controls we help customers operate. Here is how we protect your data, in plain language.

Encryption everywhere

TLS for every connection in transit. Encryption at rest for the database and file storage.

Strong authentication

Sign in is handled by a dedicated identity provider with MFA support and revocable sessions.

Tenant isolation

Records and storage paths are scoped to your organization, with membership checks before protected data is read or delivered.

Least privilege

Sensitive in-product actions are role gated and recorded in an organization-scoped audit trail.

Hardened infrastructure

We build on managed platforms with strong security track records instead of running our own servers.

AI with boundaries

AI features only see the data needed for the task, scoped to your organization. Your data is not used to train models.

Subprocessors

The services that touch your data, and why.

VercelApplication hosting and file storage
NeonPostgres database
ClerkAuthentication and organization management
AnthropicAI generation
StripeSubscription billing and payment processing
ResendTransactional email
UpstashRate limiting and lead storage

Found something?

We welcome good faith security research. Report vulnerabilities to security@vciso.ai and we will respond quickly, credit you if you want it, and never take legal action against good faith research.

Trust is the product.

See how we help you build the same kind of program for your customers.