vCISO.ai is designed around the same security controls we help customers operate. Here is how we protect your data, in plain language.
TLS for every connection in transit. Encryption at rest for the database and file storage.
Sign in is handled by a dedicated identity provider with MFA support and revocable sessions.
Records and storage paths are scoped to your organization, with membership checks before protected data is read or delivered.
Sensitive in-product actions are role gated and recorded in an organization-scoped audit trail.
We build on managed platforms with strong security track records instead of running our own servers.
AI features only see the data needed for the task, scoped to your organization. Your data is not used to train models.
The services that touch your data, and why.
We welcome good faith security research. Report vulnerabilities to security@vciso.ai and we will respond quickly, credit you if you want it, and never take legal action against good faith research.
See how we help you build the same kind of program for your customers.