vCISO.AI runs its own security program on vCISO.AI. Here is how we protect your data, in plain language.
TLS for every connection in transit. Encryption at rest for the database and file storage.
Sign in is handled by a dedicated identity provider with MFA support. Sessions are short lived and revocable.
Every record is scoped to your organization and every query is checked against your membership. No shared buckets, no cross tenant reads.
Production access is limited to the people who operate the service, with audit trails on administrative actions.
We build on managed platforms with strong security track records instead of running our own servers.
AI features only see the data needed for the task, scoped to your organization. Your data is not used to train models.
The services that touch your data, and why.
We welcome good faith security research. Report vulnerabilities to security@vciso.ai and we will respond quickly, credit you if you want it, and never take legal action against good faith research.
See how we help you build the same kind of program for your customers.