Least privilege
People and integrations receive only the access needed for an authorized task.
Security & Trust
Security practicesUnderstand how vCISO.ai protects customer data, separates workspaces, uses AI providers, and keeps material decisions under human control.
Workspace protection
Current product boundaries
Security principles
vCISO.ai handles program records that may be sensitive. Authentication, tenant scope, data minimization, and human approval are enforced in the application rather than left to marketing promises.
Review released read-only integrationsPeople and integrations receive only the access needed for an authorized task.
Protected reads, mutations, downloads, and relationships stay scoped to the authorized organization.
HTTPS protects data in transit, managed services encrypt stored data, and connector credentials are encrypted before storage.
Available connectors collect supported observations and do not change customer systems.
Customer content is not used to train AI models, and AI cannot approve its own conclusions.
Authorized people approve policies, evidence, exceptions, and risk decisions.
Data flow and architecture
This customer-level view explains the systems involved without exposing credentials, internal hostnames, or sensitive infrastructure detail.
Encrypted application traffic
Session and organization membership
Authorization and product workflows
Tenant-scoped records and private artifacts
Supported observations from authorized systems
Minimized context for requested generation
Clerk handles sign-in, sessions, and organization membership. Protected product reads and mutations also resolve local organization, user, membership, and role state near the requested data. UI visibility alone never grants access.
HTTPS protects browser traffic. Managed database and private object-storage services encrypt stored data. Connector credentials are encrypted before storage, and OAuth state is short-lived, signed, and bound to the organization and provider.
Content is sent to the AI provider only when an authorized product task requests generation. Context is minimized to the task. Customer content is not used to train AI models. AI cannot approve evidence, make risk decisions, change external systems, or issue an audit result.
Customers own submitted content and generated work product. Supported exports are available in the product, and deletion can be requested after cancellation subject to the short wind-down and legal exceptions described in the current Terms and Privacy Policy. No exact backup-deletion interval is promised.
The application uses role-aware authorization, audit history for real state changes, rate limiting, monitored errors, dependency review, secure development checks, and managed infrastructure. Error monitoring is scrubbed to retain safe categories and limited diagnostic tags rather than customer content.
Service providers
These providers support the released product. Their role does not imply that vCISO.ai holds the provider's certifications.
| Provider | Purpose | High-level data |
|---|---|---|
| Vercel | Application hosting and private object storage | Application traffic and stored customer artifacts |
| Neon | Managed Postgres database | Organization-scoped application records |
| Clerk | Authentication and organization membership | Identity, session, and membership information |
| Anthropic | Optional AI generation | Minimized context for an authorized AI request |
| Stripe | Subscription billing and payment processing | Billing account and payment information |
| Resend | Transactional email | Recipient and message delivery information |
| Upstash | Rate limiting and public lead persistence | Rate-limit keys and submitted lead fields |
| Sentry | Application error monitoring | Minimized error category and safe diagnostic tags |
Documents and requests
Review the commitments published today or contact our security team with a specific request.
Data collection, use, export, and deletion requests.
Open Privacy PolicyService, customer responsibility, AI review, and outcome boundaries.
Open Terms of ServiceAsk a security question or report a concern.
Open Security contactReport the affected route, integration, or component and reproduction steps. Do not include credentials, access customer data, perform destructive testing, or degrade availability. No response-time commitment is stated.
Open Vulnerability disclosureStart with the roadmap
Tell vCISO.ai about your company and target audit, then see the first control your team should complete.