Trust Center
Data Protection

How we protect your data

Technical and organizational security measures we implement to keep your compliance data safe.

Security controls

Defense in depth across every layer of our stack.

Encryption

  • AES-256 encryption at rest for all customer data
  • TLS 1.3 encryption in transit for all connections
  • Database-level encryption with Google Cloud KMS managed keys
  • Encrypted backups stored in geographically separate regions

Access controls

  • Role-based access control (RBAC) throughout the platform
  • Multi-factor authentication required for all employee access
  • Principle of least privilege enforced across all systems
  • Quarterly access reviews and automated deprovisioning

Infrastructure

  • Hosted on Google Cloud Platform (SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS attested at the infrastructure layer)
  • Virtual private cloud (VPC) isolation for all environments
  • Cloud Armor WAF protecting all endpoints
  • Built-in Google Cloud DDoS protection

Monitoring

  • 24/7 security monitoring and alerting
  • Real-time intrusion detection and prevention
  • Centralized logging with 12-month retention
  • Automated vulnerability scanning (weekly)

Security architecture

Layered security controls at every level

Network
VPC isolation, WAF, DDoS protection, private subnets, network ACLs
Application
Input validation, output encoding, CSRF protection, secure headers, CSP
Data
AES-256 encryption, field-level encryption for sensitive data, key rotation
Identity
OAuth 2.0, MFA support, session management, secure token handling
Operational
CI/CD security scanning, infrastructure as code, change management

Security practices

How we maintain and improve our security posture.

Incident response

We maintain a documented incident response plan with defined roles, escalation procedures, and communication protocols. Our mean time to detect is under 15 minutes, and we commit to notifying affected customers within 72 hours of confirmed breaches.

Business continuity

Daily encrypted backups with 30-day retention. Recovery point objective (RPO) of 1 hour, recovery time objective (RTO) of 4 hours. Annual disaster recovery testing with documented results.

Vendor management

All vendors with access to customer data undergo security assessment. We maintain a vendor risk register, require SOC 2 reports or equivalent, and include data protection clauses in all contracts.

Penetration testing

Annual third-party penetration testing by qualified security firms. Continuous bug bounty program for responsible disclosure. All critical and high findings remediated within 30 days.

Compliance frameworks

Third-party validated security and compliance.

SOC 2 Type I

Working toward our SOC 2 Type I report, managed via vCISO Lite itself. Report will be linked here when signed.

In progress

CAIQ (CSA STAR)

Consensus Assessments Initiative Questionnaire in progress. Work-in-progress responses available on request.

In progress

GDPR

Privacy posture handled via our published Privacy Policy and DPA, with EU Standard Contractual Clauses available on request.

Posture-only

CCPA

Privacy posture covered by our Privacy Policy and consumer-rights workflow. Data deletion and access requests honored via security@vcisolite.com.

Posture-only

ISO 27001

Not currently on our roadmap. We support ISO 27001 prep for our customers regardless.

Not on roadmap

PCI DSS

Not applicable — we don't process, store, or transmit cardholder data. Billing runs through a PCI-compliant processor.

Not applicable

Data residency

By default, customer data is stored in Google Cloud Platform us-central1 (Iowa) with backups replicated to us-central. Enterprise customers can request data residency in EU regions on request.

Primaryus-central1 (Iowa)
Backupus-central
EU Optioneurope-west (on request)

Need more details?

Download our security documentation package including SOC 2 report, penetration test summary, and completed security questionnaire.