Security

Trust Center

Security and compliance are built into everything we do.

Security contact: security@vistaan.com

Data Protection

Encryption, access controls, and audit trails for all customer data.

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest
  • Least-privilege access
  • Role-based controls
  • Audit logging

Secure Delivery

Peer review, automated testing, and secure CI/CD pipelines on every release.

  • Peer review
  • Automated testing
  • CI/CD checks
  • Secrets management
  • Dependency scanning

Infrastructure

Hardened cloud environments with network segmentation, backups, and observability.

  • Hardened cloud
  • Network segmentation
  • Backups
  • Observability

Incident Readiness

24/7 alerting, runbooks, and clear communication during security events.

  • 24/7 alerting
  • Runbooks
  • Post-incident reviews
  • Clear SLAs
  • Communication channels

Secure SDLC

Development

We use peer reviews, automated tests, dependency scanning, and secrets management in CI/CD.

Environments

Environments are separated for development, staging, and production with explicit promotion steps.

Reviews

We regularly review architecture for threat modeling and update controls as systems evolve.

Data Handling

We limit access to production data to authorized personnel on a need-to-know basis.

Customer data is isolated by environment with backups stored in encrypted, access-controlled vaults.

We maintain audit logs for administrative actions, access attempts, and configuration changes.

SOC 2 Type II

Annual audit with independent third-party assessment of our security controls.

ISO 27001

Information security management system for systematically securing data.

GDPR

EU data protection regulation compliance for all customer data handling.

PCI-DSS Level 1

Payment card industry data security standard for handling cardholder data.

HIPAA Awareness

Health data protection best practices followed for applicable engagements.

Have questions about our security practices?