What Data VISO TRUST Collects
VISO TRUST collects only the information necessary to assess third-party security risk. This includes: From your vendors (via collection requests):- Security and compliance audit reports (SOC 2, ISO 27001, HITRUST, PCI DSS, etc.)
- Penetration testing results
- Privacy and compliance documents (DPAs, privacy policies)
- Cyber insurance policies
- AI governance documentation
- Questionnaire responses
- Publicly available security and compliance documentation
- Vendor security and privacy pages
- Compliance certification claims
- Breach disclosures and risk advisories from public feeds
- Relationship context and configuration
- Internal user data (names, emails, roles)
- Organization settings and preferences
How Data Is Protected
Encryption
All data is encrypted in transit using TLS and at rest using industry-standard encryption protocols. This applies to vendor-submitted documents, assessment data, and all platform communications.Access Control
Access to data within VISO TRUST is controlled at multiple levels:- Role-based access limits what each user can see and do within your organization’s instance
- Organization isolation ensures data from one VISO TRUST customer is never accessible to another
- Vendor data scoping means vendor-submitted artifacts are accessible only to the client organization that requested them — not to other VISO TRUST customers assessing the same vendor
Secure Document Submission
Vendor documents are submitted through encrypted portals using one-time passcodes. The submission experience is designed to prevent unauthorized access and ensure that only the designated vendor contact can submit documentation.Credential Handling
For integrations that use delegated authorization (such as Slack), VISO TRUST relies on the provider’s own authorization flow rather than storing your credentials. Where an integration requires credentials directly (such as Coupa API keys), they are stored securely server-side. API tokens are presented once at generation and should be stored securely by the user.Vendor Data and Confidentiality
Vendor documents are not shared across customers. When a vendor submits a SOC 2 report to satisfy your assessment, that document is not shared with other VISO TRUST customers who assess the same vendor. Each assessment is isolated to the client-vendor relationship it belongs to. Trust Profile artifacts are not public. Documents uploaded to your organization’s Trust Profile are used internally — to answer AI-generated questionnaire queries and power Vendor Discovery — and are not shared outside your VISO TRUST instance without your action. Publicly collected artifacts are sourced from information vendors have made publicly available (their own website, public trust portals, etc.). VISO TRUST does not access non-public systems or credentials.Auditor Access
When the AI Assessment + Auditor Review method is configured, VISO TRUST analysts access submitted artifacts to perform a focused review of high-assurance documents. This access is:- Scoped to the specific artifacts under review
- Logged and auditable
- Performed only by trained VISO TRUST personnel under confidentiality obligations