How we protect your data
Technical and organizational security measures we implement to keep your compliance data safe.
Security controls
Defense in depth across every layer of our stack.
Encryption
- AES-256 encryption at rest for all customer data
- TLS 1.3 encryption in transit for all connections
- Database-level encryption with Google Cloud KMS managed keys
- Encrypted backups stored in geographically separate regions
Access controls
- Role-based access control (RBAC) throughout the platform
- Multi-factor authentication required for all employee access
- Principle of least privilege enforced across all systems
- Quarterly access reviews and automated deprovisioning
Infrastructure
- Hosted on Google Cloud Platform (SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS attested at the infrastructure layer)
- Virtual private cloud (VPC) isolation for all environments
- Cloud Armor WAF protecting all endpoints
- Built-in Google Cloud DDoS protection
Monitoring
- 24/7 security monitoring and alerting
- Real-time intrusion detection and prevention
- Centralized logging with 12-month retention
- Automated vulnerability scanning (weekly)
Security architecture
Layered security controls at every level
Security practices
How we maintain and improve our security posture.
Incident response
We maintain a documented incident response plan with defined roles, escalation procedures, and communication protocols. Our mean time to detect is under 15 minutes, and we commit to notifying affected customers within 72 hours of confirmed breaches.
Business continuity
Daily encrypted backups with 30-day retention. Recovery point objective (RPO) of 1 hour, recovery time objective (RTO) of 4 hours. Annual disaster recovery testing with documented results.
Vendor management
All vendors with access to customer data undergo security assessment. We maintain a vendor risk register, require SOC 2 reports or equivalent, and include data protection clauses in all contracts.
Penetration testing
Annual third-party penetration testing by qualified security firms. Continuous bug bounty program for responsible disclosure. All critical and high findings remediated within 30 days.
Compliance frameworks
Third-party validated security and compliance.
SOC 2 Type I
Working toward our SOC 2 Type I report, managed via vCISO Lite itself. Report will be linked here when signed.
CAIQ (CSA STAR)
Consensus Assessments Initiative Questionnaire in progress. Work-in-progress responses available on request.
GDPR
Privacy posture handled via our published Privacy Policy and DPA, with EU Standard Contractual Clauses available on request.
CCPA
Privacy posture covered by our Privacy Policy and consumer-rights workflow. Data deletion and access requests honored via security@vcisolite.com.
ISO 27001
Not currently on our roadmap. We support ISO 27001 prep for our customers regardless.
PCI DSS
Not applicable — we don't process, store, or transmit cardholder data. Billing runs through a PCI-compliant processor.
Data residency
By default, customer data is stored in Google Cloud Platform us-central1 (Iowa) with backups replicated to us-central. Enterprise customers can request data residency in EU regions on request.
Need more details?
Download our security documentation package including SOC 2 report, penetration test summary, and completed security questionnaire.