Third Party Index

Snapshot 22058

Document
Security page
URL
https://viktor.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
433639 bytes
SHA-256 (raw)
9145fe3dc28154ed224e3e7ef4f636d83d9c3103de5e62ed9029c7b814169984
SHA-256 (normalized text)
df41135ec7624086b343e220070be8db6bd1c2c5d31ecbe2afc82d161f4c09a5

Normalized text

Scripts and page chrome removed; this is what change detection compares.

The security behind your AI employee.
Built so your credentials never touch the AI, every sensitive action waits for approval, and your data never trains a model.
Get Started for Free
SOC 2 compliant
GDPR aligned
CCPA compliant
CASA Tier 3
ChatGPT
ChatGPT in Slack: Search, write, summarize and get work done.
Claude
Anthropic's AI agent for any task — think, write, and code with Claude.
Viktor
Your AI employee in Slack
Compliance
Independently audited. Continuously verified.
The audit reports are real, the controls are continuously monitored, and the next audit is always on the calendar.
Standard
Status
Coverage
Documentation
SOC 2 Type 1
Status
Certified
Coverage
Independent attestation that our security controls operate as designed. Type II in progress.
Documentation
Report available under NDA.
GDPR
Status
Aligned
Coverage
EU data protection requirements met.
Documentation
DPA available on request.
CCPA
Status
Compliant
Coverage
California Consumer Privacy Act requirements met.
Documentation
Privacy documentation available.
Slack App Directory
Status
Listed
Coverage
OAuth scopes and security posture vetted before shipment through the Slack store.
Documentation
Public App Directory listing.
ISO 27001
Status
In progress
Coverage
ISMS controls implementation and evidence collection in progress.
Documentation
Controls overview available today; audit evidence shared after certification.
Data handling
What Viktor does. What Viktor does not.
Here's exactly what Viktor touches — and what he never does.
Does
Encrypts everything
TLS 1.2+ in transit. AES-256 at rest. Secrets in dedicated vaults.
Authenticates with SSO
SAML SSO across Okta (inside Slack), Entra ID, Google Workspace, OneLogin and any SAML 2.0 IdP.
Data residency options
US-hosted by default. EU data residency available on Enterprise contracts.
Revokes instantly
Admins can disconnect any integration, pause any user, or kill a running task in one click.
Does not
Train on your data
Your conversations and files never enter a training set — not ours, not our model providers'.
Read your secrets
API keys and tokens are injected at execution time by the tool gateway; the model never sees them.
Act without approval
Money moves, code pushes, and customer emails wait for your explicit approval in Slack.
Share across workspaces
Skills, integrations, and memory are walled off per workspace. No cross-tenant access.
AI Safety
AI brings new risks, and we know how to handle them
A backend tool gateway injects your API keys and OAuth tokens at execution time. The AI model itself never sees them.
Not a policy. The architecture.
model-context-preview
Task
Sync HubSpot MQLs
to Salesforce
OAuth token
[Redacted]
API key
[Not Available]
tool-gateway
Credential
Injected server-side
Vault
AES-256 at rest
Audit
Access logged
Viktor vs AI tools
Independently audited.
AI brings new risks, and we know how to handle them
AI employees introduce attack surfaces traditional SaaS does not have. Three controls keep the surface small.
Prompt-injection defense
Untrusted content is rendered as data, not commands. Admins put high-risk tools behind human approval, so an injection can't trigger gated actions like moving money or pushing code on its own.
Named model providers, no-training contracts
Inference runs on OpenAI, Anthropic, and Google. Each is on the public sub-processor list with a no-training agreement for Viktor traffic.
Skills, the persistent memory
Memory is scoped to your workspace, encrypted at rest, never used to train models, and fully exportable or deletable on request.
Credentials & secrets
3,200+ integrations. Zero secrets in chat.
OAuth-first
Every major tool connects via OAuth with the narrowest scopes that get the job done. No passwords stored.
Encrypted vault
Where API keys are required, they are stored in a secrets vault, AES-256 at rest, isolated from model context, access-logged, and rotatable.
Admin scope control
Admins decide which integrations are connected, who can use them, and at what level. Revoke any integration in one click.
Vulnerability disclosure
If you believe you have found a security vulnerability in Viktor, we want to hear from you. Email [email protected] with enough detail to reproduce the issue: affected URL or component, steps, impact, and any proof-of-concept. Please do not include customer data in the report.
Scope
viktor.com, app.viktor.com, api.viktor.com, the Viktor Slack and Microsoft Teams apps, and the Viktor desktop apps. Third-party services we integrate with are out of scope; report those to the vendor.
Our commitments
Acknowledgement within 5 business days of receiving your report.
Triage result and status update within 30 calendar days, and further updates at least every 30 days until resolution.
Confirmed critical vulnerabilities fixed within 90 calendar days of confirmation; other severities according to our internal remediation targets, which are stricter than this.
We coordinate public disclosure with you once a fix is released, and we credit reporters who want credit.
What we ask of you
give us reasonable time to remediate before public disclosure, do not access or modify data that is not yours, do not degrade the service (no DoS, spam, or social engineering of staff or customers), and stop and report immediately if you encounter customer data.
Safe harbor
research that follows this policy is authorized, and we will not pursue or support legal action against you for it. If a third party takes action against you for activity conducted in accordance with this policy, we will make it known that you acted in good faith.
Recognition
we do not run a paid bug bounty today. Meaningful reports receive a thank-you, public credit if wanted, and Viktor credits.
Send security report
FAQ
Email [email protected]. We acknowledge within 5 business days, provide triage status within 30 days, and fix confirmed critical issues within 90 days. Full policy under Vulnerability disclosure on this page; machine-readable contact at /.well-known/security.txt.
4.9 on G2G2 rating: 4.9 out of 5 stars
One hire. The output of a team.
Viktor works nights, remembers every decision, and connects to 3,200 tools. Start free with $100 in credits, then $50 a month.
Get Started For FreeSee all plans
Book a DemoSee all plans
Book a Demo