FAQ

Frequently Asked Questions

Quick answers to common questions about vCISO Lite

Getting Started

vCISO Lite produces the security deliverables that close deals, satisfy investors, and pass audits—questionnaire responses, compliance documentation, policies, and evidence packages. It's built for companies that need these outputs now but aren't ready to build a full security organization yet.

Most customers complete their initial setup in under 30 minutes. You can run your first gap analysis within an hour of signing up, and our AI will help you understand your security posture immediately.

No deep security expertise required to get started. The platform guides you through each step with clear explanations and handles the technical complexity behind the scenes. As your security maturity grows, the platform grows with you—it's just as useful for a founding team as it is for a dedicated security leader.

We integrate with GitHub, GitLab, AWS, Azure, GCP, Okta, Google Workspace, Microsoft 365, and 30+ other systems for automated evidence collection and posture monitoring. See the live integration list — with what each connector actually pulls — at /features/integrations. If we're missing something critical to your stack, ask us in a demo; connector priorities shift with customer need.

Compliance & Security

vCISO Lite supports SOC 2, ISO 27001, NIST CSF, HIPAA, PCI DSS, and GDPR — and 8 others out of the box, with new frameworks added monthly. Our gap analysis maps your current practices against any of them and identifies exactly what you need to address.

Yes. vCISO Lite helps you prepare for SOC 2 by identifying gaps, generating required policies, and compiling evidence packages. While we don't perform audits ourselves, our customers typically achieve SOC 2 readiness in 6-8 weeks with our platform.

When you receive a security questionnaire from a prospect or customer, upload it to vCISO Lite. Our AI analyzes your existing documentation, policies, and controls to draft responses. You review and approve before sending—no more starting from scratch every time.

Policies & Documentation

Our policy templates are developed with input from compliance professionals and are regularly updated to reflect current standards. However, we recommend having legal counsel review any policies before formal adoption, especially in regulated industries.

Absolutely. All generated policies are fully editable. You can adjust language, add company-specific procedures, and tailor controls to match your actual practices. The goal is policies that reflect reality, not boilerplate.

Pricing & Plans

Pricing starts at $299/month for small teams. We offer plans scaled to your organization size and compliance needs. Visit our pricing page for detailed information, or contact us for a custom quote.

Pick the plan that fits your business on our pricing page, and you'll be up and running the same day. Every plan includes onboarding support to help you hit the ground running.

Yes. All plans are month-to-month with no long-term contracts required. You can cancel anytime, and you'll retain access through the end of your billing period.

Security & Privacy

All data is encrypted at rest (AES-256) and in transit (TLS 1.3), with multi-factor authentication required for all employee access. We're actively pursuing SOC 2 Type I, managed via vCISO Lite itself. See our Trust Center for current compliance posture, what we hold, and what we're working toward.

Yes. Our own SOC 2 Type I audit is in progress (Q4 2026 target) and every control, policy, and evidence artifact runs on the same platform we sell — including the CAIQ questionnaire we're completing in parallel. Our public timeline, current audit stage, and (when the report lands) the auditor's name are all published at /trust/compliance. We're not asking you to run a program we haven't run ourselves.

All customer data is stored on Google Cloud Platform in the United States, with multi-region redundancy for reliability. GCP holds SOC 2, ISO 27001, ISO 27017, ISO 27018, and PCI DSS attestations at the infrastructure layer.

No. Your data is never used to train our AI models or shared with third parties for model training. Your information stays yours.

Support

All plans include email support with 24-hour response times. Professional and Enterprise plans include live chat, priority support, and dedicated success managers.

Yes. Our Enterprise plan includes guided implementation with a dedicated compliance advisor. We also offer professional services for customers who need hands-on assistance with their compliance programs.

On a discovery call, we can share the exact controls we've implemented on vCISO Lite for our own SOC 2 Type I program, the auditor we've engaged, our current gap-remediation status, the founder's compliance background, and a live walkthrough of every feature running against a synthetic profile shaped like yours. When we have referenceable customers, they'll be published on this page — with names and outcomes, not logo walls.

Still have questions?

Our team is happy to help. Reach out and we'll get back to you within 24 hours.

Ready to simplify security?

See how easy it can be.