Third Party Index

Snapshot 27616

Document
Trust center
URL
https://visualping.io/trust
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
345891 bytes
SHA-256 (raw)
1267b69bb667dcfea9c3edd2ca2c6df7f4717e9715aaad656229d29b42d3af4c
SHA-256 (normalized text)
e8df3bdc4820bfb82685b60480fd23fafa244fac757aacc7d7b90a04323d2184

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Last updated September 16, 2026
Visualping Trust Center
Enterprise-grade security, compliance and privacy. Here’s how we protect what you share with us, and how to verify it yourself.
Request security documents
SOC 2 audit underway
DPA on every business plan
Our compliance postureIn progressSOC 2GDPRCCPAPIPEDA
Compliance
Our current certifications and the standards we align to. Reports are available on request under NDA.
In progress
SOC 2 Type I
Point-in-time assessment of our security controls, in preparation with an independent CPA firm. Report expected Q4 2026.
Planned
SOC 2 Type II
Ongoing assessment across an observation window. Planned following our Type I report.
Aligned
GDPR
We process personal data in line with the EU General Data Protection Regulation. DPA available on request.
Aligned
CCPA
We honor privacy rights under the California Consumer Privacy Act.
How we protect your data
The security practices behind Visualping, grouped by the areas our SOC 2 program covers.
Access control
MFA enforced everywhere, SSO where available, least-privilege role-based access, and quarterly access reviews.
Encryption
Data encrypted in transit (TLS) and at rest, with full-disk encryption on all company devices. Secrets managed through our cloud provider's key management.
Monitoring & logging
Production activity is logged and monitored with alerting on anomalous behavior, endpoint detection and response on all devices, and activity logs retained for 12 months.
Change management
All changes go through code review and approval, with separation of development and production environments.
Resilience
Automated, encrypted, immutable backups with restore testing, plus a documented incident response and business continuity plan with a 4-hour recovery time objective.
People & training
Background checks where lawful, signed confidentiality agreements, and security awareness training for all staff.
Subprocessors
Third parties that may process customer data on our behalf.
Subprocessor	Purpose	Location
Amazon Web Services	Cloud hosting, storage, email delivery	United States
OpenAI	AI change analysis & chat assistant	United States
Anthropic	AI change analysis & chat assistant	United States
Google	AI change analysis (Gemini), chat assistant & reCAPTCHA	United States
Microsoft Azure	AI change analysis	United States
Stripe	Billing & payments	United States
PayPal	Payments	United States
Front	Customer support	United States
HubSpot	CRM & marketing forms	United States
FormCrafts	Contact & demo request forms	Germany
Mixpanel	Product analytics	United States
Honeycomb	Application observability	United States
For your security review
Get the documents your team will ask for
Security whitepaper, Data Processing Agreement and our full Risk Ledger security assessment with supporting evidence — shared under NDA, usually within one business day.
Security whitepaper
Data Processing Agreement (DPA)
Risk Ledger security assessment
Request access
FAQ
What security teams ask before they sign
Where is our data stored?
In AWS United States regions (us-west-2, Oregon). Backups are encrypted, immutable and tested regularly.
Do you access content behind our logins?
Only if you configure credentialed monitoring. Credentials are encrypted and used solely to load the page you specify.
Can you monitor sites on our private network?
No. Visualping is a hosted service: our capture workers run in AWS and can only reach URLs that are publicly routable from the internet. A monitor pointed at an intranet hostname or a private IP address is accepted by the form, but its checks will fail. There is no on-premise or self-hosted deployment, and no agent that runs inside your network. Pages that are publicly reachable but sit behind a login are supported through credentialed monitoring.
Is our data used to train AI models?
No. Client data processed by AI-powered features is never used for model training, and is discarded once processing completes.
When will SOC 2 be complete?
The Type I assessment is underway with an independent CPA firm and the report is expected Q4 2026, with the Type II audit to follow. Reports will be shared under NDA.
Will you complete our security questionnaire?
Yes — SIG and SIG Lite, CAIQ, and your own custom questionnaire. Email it to [email protected]. Our Risk Ledger security assessment is already complete and covers the same ground, so request that as well if your review needs answers before the questionnaire comes back.
Who are your subprocessors?
AWS for hosting and email, Stripe and PayPal for payments, OpenAI, Anthropic, Google and Microsoft Azure for AI features, and a small set of support, analytics and monitoring vendors — the full list with purposes and locations is in the subprocessors section above.
Who owns security at Visualping?
We have an appointed security lead and a nominated Data Protection Officer, with security policies reviewed and approved by senior management annually.
How do I report a vulnerability?
Email [email protected]. We acknowledge every report within one business day.
Stay in the know — securely
Questions from your security team? We’ll help you fill in the questionnaire, usually within a day.
Contact security teamReport a vulnerability
[email protected] policy