Snapshot 27681
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Last updated September 16, 2026 Visualping Trust Center Enterprise-grade security, compliance and privacy. Here’s how we protect what you share with us, and how to verify it yourself. Request security documents SOC 2 audit underway DPA on every business plan Our compliance postureIn progressSOC 2GDPRCCPAPIPEDA Compliance Our current certifications and the standards we align to. Reports are available on request under NDA. In progress SOC 2 Type I Point-in-time assessment of our security controls, in preparation with an independent CPA firm. Report expected Q4 2026. Planned SOC 2 Type II Ongoing assessment across an observation window. Planned following our Type I report. Aligned GDPR We process personal data in line with the EU General Data Protection Regulation. DPA available on request. Aligned CCPA We honor privacy rights under the California Consumer Privacy Act. How we protect your data The security practices behind Visualping, grouped by the areas our SOC 2 program covers. Access control MFA enforced everywhere, SSO where available, least-privilege role-based access, and quarterly access reviews. Encryption Data encrypted in transit (TLS) and at rest, with full-disk encryption on all company devices. Secrets managed through our cloud provider's key management. Monitoring & logging Production activity is logged and monitored with alerting on anomalous behavior, endpoint detection and response on all devices, and activity logs retained for 12 months. Change management All changes go through code review and approval, with separation of development and production environments. Resilience Automated, encrypted, immutable backups with restore testing, plus a documented incident response and business continuity plan with a 4-hour recovery time objective. People & training Background checks where lawful, signed confidentiality agreements, and security awareness training for all staff. Subprocessors Third parties that may process customer data on our behalf. Subprocessor Purpose Location Amazon Web Services Cloud hosting, storage, email delivery United States OpenAI AI change analysis & chat assistant United States Anthropic AI change analysis & chat assistant United States Google AI change analysis (Gemini), chat assistant & reCAPTCHA United States Microsoft Azure AI change analysis United States Stripe Billing & payments United States PayPal Payments United States Front Customer support United States HubSpot CRM & marketing forms United States FormCrafts Contact & demo request forms Germany Mixpanel Product analytics United States Honeycomb Application observability United States For your security review Get the documents your team will ask for Security whitepaper, Data Processing Agreement and our full Risk Ledger security assessment with supporting evidence — shared under NDA, usually within one business day. Security whitepaper Data Processing Agreement (DPA) Risk Ledger security assessment Request access FAQ What security teams ask before they sign Where is our data stored? In AWS United States regions (us-west-2, Oregon). Backups are encrypted, immutable and tested regularly. Do you access content behind our logins? Only if you configure credentialed monitoring. Credentials are encrypted and used solely to load the page you specify. Can you monitor sites on our private network? No. Visualping is a hosted service: our capture workers run in AWS and can only reach URLs that are publicly routable from the internet. A monitor pointed at an intranet hostname or a private IP address is accepted by the form, but its checks will fail. There is no on-premise or self-hosted deployment, and no agent that runs inside your network. Pages that are publicly reachable but sit behind a login are supported through credentialed monitoring. Is our data used to train AI models? No. Client data processed by AI-powered features is never used for model training, and is discarded once processing completes. When will SOC 2 be complete? The Type I assessment is underway with an independent CPA firm and the report is expected Q4 2026, with the Type II audit to follow. Reports will be shared under NDA. Will you complete our security questionnaire? Yes — SIG and SIG Lite, CAIQ, and your own custom questionnaire. Email it to [email protected]. Our Risk Ledger security assessment is already complete and covers the same ground, so request that as well if your review needs answers before the questionnaire comes back. Who are your subprocessors? AWS for hosting and email, Stripe and PayPal for payments, OpenAI, Anthropic, Google and Microsoft Azure for AI features, and a small set of support, analytics and monitoring vendors — the full list with purposes and locations is in the subprocessors section above. Who owns security at Visualping? We have an appointed security lead and a nominated Data Protection Officer, with security policies reviewed and approved by senior management annually. How do I report a vulnerability? Email [email protected]. We acknowledge every report within one business day. Stay in the know — securely Questions from your security team? We’ll help you fill in the questionnaire, usually within a day. Contact security teamReport a vulnerability [email protected] policy