Trust Center
Compliance

Compliance posture

No badges we haven’t earned. Here’s what we’re actively pursuing, our audit timeline, and what you can verify today. Updated as things change.

Where we are

Building a security program in public is uncomfortable. It’s also the honest way to do it. The entire program runs on vCISO Lite — same platform we sell, same evidence pipeline our customers will use.

SOC 2 Type I

In progress — pursuing

Working toward our SOC 2 Type I report using vCISO Lite itself. Policies, evidence collection, and gap remediation all run on the same platform we sell. When the report lands, it'll be linked here with the auditor's name on it.

CAIQ (CSA STAR)

In progress — pursuing

Completing the Consensus Assessments Initiative Questionnaire via vCISO Lite. CAIQ is the same questionnaire enterprise procurement teams send to vendors — answering it ourselves before our customers have to ask.

Compliance timeline

Our journey to multi-framework compliance, including expected milestones.

Q4 2025

Security program kickoff

Began running our own security program on vCISO Lite. Initial policy library generated; baseline gap analysis complete.

Q1 2026

Control implementation

Implemented and operationalized controls against SOC 2 trust service criteria. Evidence collection pipeline live.

Q2 2026

SOC 2 Type I prep underway

Auditor selected, scoping locked, evidence packages assembled. CAIQ responses in progress in parallel.

Q3 2026

SOC 2 Type I audit window

Expected audit fieldwork window. Bridge letter cadence and continuous-monitoring evidence flowing from vCISO Lite.

Q4 2026

SOC 2 Type I report (expected)

Target: signed SOC 2 Type I report published to this page with the auditor's name on it. CAIQ posted publicly.

2027

SOC 2 Type II observation period

Begin 12-month Type II observation period using the same evidence pipeline. Report expected late 2027 / early 2028.

What you can verify today

Public artifacts and third-party attestations available right now, no NDA required.

Privacy policy

Current privacy policy with collection, processing, and retention practices.

Data protection details

Encryption, access controls, hosting attestation references, and infrastructure posture.

Responsible AI policy

How we use AI in the product and how we treat customer data in AI workflows.

GCP infrastructure attestations

Google Cloud Platform's third-party SOC 2, ISO 27001/27017/27018, and PCI DSS attestations for the platform we run on.

Available on request

For vendor security assessments or procurement reviews, email security@vcisolite.com. We typically respond within one business day.

Security questionnaire (CAIQ in progress)

We can share work-in-progress CAIQ responses on request. Full CAIQ posted publicly when complete.

Data Processing Agreement

Standard DPA with EU Standard Contractual Clauses, available on request.

Penetration test summary

Executive summary from our most recent third-party pentest, under NDA.

Insurance certificates

Cyber liability and E&O insurance certificates available on request.

Need details for your security review?

We understand vendor security assessments. The SOC 2 Type I report is in progress; in the meantime, tell us what your procurement team needs and we’ll respond with the actual artifacts available today.