Trust Center
Privacy

Privacy Policy

How we collect, use, and protect your personal information. Last updated: June 2026.

The short version

We collect only what we need to provide our service. We never sell your data or use it to train AI. Your compliance documentation stays yours—we're just the platform that helps you manage it. You can export or delete your data anytime.

Information we collect

We collect information you provide directly:

  • Account information: Name, email address, company name, and billing information when you create an account.
  • Organization data: Security policies, compliance documentation, questionnaire responses, and other content you create or upload to the platform.
  • Communications: Messages you send to our support team, feedback you provide, and survey responses.

We also collect information automatically:

  • Usage data: How you interact with our platform, features you use, and actions you take.
  • Device information: Browser type, operating system, IP address, and device identifiers.
  • Cookies: We use essential cookies for authentication and preferences. See our cookie section below.

How we use your information

We use your information to:

  • Provide our services: Generate policies, run gap analyses, answer questionnaires, and deliver the core vCISO Lite functionality.
  • Improve the platform: Understand usage patterns, identify bugs, and develop new features. We analyze aggregate, anonymized data—never individual customer content.
  • Communicate with you: Send service updates, security alerts, billing notices, and respond to support requests.
  • Ensure security: Detect fraud, prevent abuse, and protect the platform and our users.
  • What we never do:
  • - Sell your data to third parties
  • - Use your content to train AI models
  • - Share your compliance documentation without your explicit consent
  • - Access your data except when necessary to provide support you've requested

AI and your data

Our platform uses AI to power features like policy generation and questionnaire responses. Here's how we handle your data:

  • Burn after reading: When you use AI features, your data is sent to our AI providers (see Responsible AI page for details), processed, and immediately discarded. It is not stored, logged, or used for training.
  • No model training: Your content is never used to train AI models—ours or anyone else's. We have data processing agreements with all AI providers that explicitly prohibit training on customer data.
  • Isolated processing: Each AI request is processed in isolation. Your data is not combined with other customers' data or retained between sessions.

For complete details on our AI practices, see our Responsible AI page.

AI clients, MCP, and plugins

vCISO Lite offers a Model Context Protocol (MCP) server and a Claude Code plugin that let you connect your own AI assistant—such as Claude, Claude Code, Claude Desktop, or Cursor—to your vCISO Lite data. This is optional and happens only when you choose to connect a client.

  • You direct the connection: Nothing is shared with an AI client unless you install the plugin or add the MCP server and sign in. You authorize access through OAuth—we never receive or store your AI provider's credentials, and your AI provider never receives your vCISO Lite password.
  • What a connected client can access: Once connected, the AI client can read the vCISO Lite data your role and organization already permit—such as compliance posture, findings, vendor records, and audit history—by calling scoped tools. Write actions (for example, triaging a finding) happen only when you direct them. Access is limited to your own organization(s) and your existing permissions; connecting a client never widens what you can see.
  • Data leaves to the provider you choose: When you use a connected AI client, your prompts and the vCISO Lite data returned to answer them are processed by that AI provider (for example, Anthropic) under that provider's own terms and privacy policy—not ours. We are the source of the data; you and the provider you chose control what happens to it inside that assistant. Review your AI provider's privacy terms before connecting.
  • We log the calls—never to train: For security and audit, we record metadata about tool calls made through the MCP server (which tool, when, by whom, and the outcome) in your organization's tamper-evident audit trail. We do not use this, or any of your content, to train AI models.
  • Disconnecting: You can revoke a client's access at any time from your account settings or by uninstalling the plugin, which stops further data sharing immediately.

For setup details, see our Developers page.

When we share information

We share information only in these limited circumstances:

  • Service providers: We work with trusted providers for hosting (Google Cloud Platform), payment processing (Stripe), and email (SendGrid). All providers are contractually bound to protect your data and are SOC 2 certified.
  • AI providers: As described above, with strict data handling requirements.
  • Legal requirements: We may disclose information if required by law, subpoena, or court order. We will notify you unless legally prohibited.
  • Business transfers: If vCISO Lite is acquired or merges with another company, your information may be transferred. We will notify you before any such transfer.
  • With your consent: We may share information when you explicitly ask us to, such as generating audit packs for your auditors.

Data retention

  • Active accounts: We retain your data for as long as your account is active and you're using our services.
  • After cancellation: When you cancel, we retain your data for 30 days in case you change your mind. After that, we delete it from our production systems within 90 days.
  • Backups: Data may persist in encrypted backups for up to 12 months for disaster recovery purposes.
  • Legal holds: We may retain data longer if required by law or to resolve disputes.
  • Export your data: You can export all your data at any time from your account settings. We provide it in standard formats (PDF, JSON) so you can take it with you.

Your rights

Depending on your location, you have rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Update or correct inaccurate information.
  • Deletion: Request deletion of your personal data (subject to legal retention requirements).
  • Portability: Export your data in a machine-readable format.
  • Objection: Object to certain processing of your data.
  • Restriction: Request that we limit how we use your data.

To exercise these rights, contact privacy@vcisolite.com or use the tools in your account settings. We respond to all requests within 30 days.

International transfers

vCISO Lite is based in the United States, and your data is processed and stored in the US.

  • EU/UK users: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers of personal data from the EU/UK to the US.
  • Data localization: Enterprise customers can request data residency in specific regions. Contact sales for details.
  • Adequacy: We continuously monitor regulatory developments and update our practices to maintain compliance with international data protection laws.

Cookies and tracking

We use a small number of cookies and a single third-party tracker. You can change your choices any time by clicking the cookie icon in the bottom-right of any page on vcisolite.com.

  • Strictly necessary (always on): Authentication, session security (CSRF, JWT), and core platform functionality. You cannot opt out of these — without them the platform doesn't function. None of these leave our infrastructure.
  • Analytics (opt-in): Google Analytics. Tells us which pages get visited and where people bounce. Aggregated traffic patterns only, not individual user tracking. We use this to prioritize what to write and what to fix.
  • Advertising (opt-in): Google Ads conversion tracking (gtag.js). Lets us see whether a click from a Google Ad turned into a real signup. No retargeting, no behavioral profiling. Used only to measure whether our ad spend is working.
  • Marketing automation (opt-in, currently unused): Reserved for future newsletter / outbound attribution. Nothing is wired up here yet — opting in or out today changes nothing.
  • Consent mechanics: We implement Google Consent Mode v2. The Google Ads and Analytics pixels default to "denied" until you explicitly choose otherwise. Your choices live in your browser's local storage, not on our servers.
  • Data processors used: Google LLC (Google Ads + Analytics, US/EU). Reviewed under our standard subprocessor process.

Our platform works with all non-essential cookies disabled.

Contact us

For privacy-related questions or to exercise your rights:

  • Email: privacy@vcisolite.com
  • Mail:
  • vCISO Lite LLC
  • Attn: Privacy Team
  • 1870 The Exchange SE Ste 220
  • PMB 851291
  • Atlanta, Georgia 30339-2171 US
  • Data Protection Officer: dpo@vcisolite.com

We take privacy seriously and respond to all inquiries within 30 days.