> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Privacy

> How VISO TRUST protects customer and vendor data: what's collected, where it's stored, encryption, access controls, and compliance certifications.

VISO TRUST is purpose-built for handling sensitive third-party risk data. This page outlines how the platform is designed to keep your data — and your vendors' data — secure and private.

## What Data VISO TRUST Collects

VISO TRUST collects only the information necessary to assess third-party security risk. This includes:

**From your vendors (via collection requests):**

* Security and compliance audit reports (SOC 2, ISO 27001, HITRUST, PCI DSS, etc.)
* Penetration testing results
* Privacy and compliance documents (DPAs, privacy policies)
* Cyber insurance policies
* AI governance documentation
* Questionnaire responses

**From public sources (via automated research):**

* Publicly available security and compliance documentation
* Vendor security and privacy pages
* Compliance certification claims
* Breach disclosures and risk advisories from public feeds

**From your organization:**

* Relationship context and configuration
* Internal user data (names, emails, roles)
* Organization settings and preferences

VISO TRUST does not collect personal data about end users of your vendors' products or any data beyond what is required for risk assessment purposes.

## How Data Is Protected

### Encryption

All data is encrypted in transit using TLS and at rest using industry-standard encryption protocols. This applies to vendor-submitted documents, assessment data, and all platform communications.

### Access Control

Access to data within VISO TRUST is controlled at multiple levels:

* **Role-based access** limits what each user can see and do within your organization's instance
* **Organization isolation** ensures data from one VISO TRUST customer is never accessible to another
* **Vendor data scoping** means vendor-submitted artifacts are accessible only to the client organization that requested them — not to other VISO TRUST customers assessing the same vendor

### Secure Document Submission

Vendor documents are submitted through encrypted portals using one-time passcodes. The submission experience is designed to prevent unauthorized access and ensure that only the designated vendor contact can submit documentation.

### Credential Handling

For integrations that use delegated authorization (such as Slack), VISO TRUST relies on the provider's own authorization flow rather than storing your credentials. Where an integration requires credentials directly (such as Coupa API keys), they are stored securely server-side. API tokens are presented once at generation and should be stored securely by the user.

## Vendor Data and Confidentiality

**Vendor documents are not shared across customers.** When a vendor submits a SOC 2 report to satisfy your assessment, that document is not shared with other VISO TRUST customers who assess the same vendor. Each assessment is isolated to the client-vendor relationship it belongs to.

**Trust Profile artifacts are not public.** Documents uploaded to your organization's Trust Profile are used internally — to answer AI-generated questionnaire queries and power Vendor Discovery — and are not shared outside your VISO TRUST instance without your action.

**Publicly collected artifacts** are sourced from information vendors have made publicly available (their own website, public trust portals, etc.). VISO TRUST does not access non-public systems or credentials.

## Auditor Access

When the **AI Assessment + Auditor Review** method is configured, VISO TRUST analysts access submitted artifacts to perform a focused review of high-assurance documents. This access is:

* Scoped to the specific artifacts under review
* Logged and auditable
* Performed only by trained VISO TRUST personnel under confidentiality obligations

Auditors do not retain copies of vendor documents after the review is complete.

## AI and Data Usage

VISO TRUST's AI models (Artifact Intelligence, VISO Chat Agent, context prediction) operate on data within your organization's instance. VISO TRUST does not use customer data to train shared AI models without explicit consent.

AI-generated outputs — risk scores, control detections, questionnaire answers — are derived from evidence in your instance and are transparent: every finding links back to a source artifact and detection.

## Compliance

VISO TRUST maintains compliance with applicable data protection regulations and industry standards. For specific compliance documentation, certifications, or data processing agreements, contact [support@visotrust.com](mailto:support@visotrust.com) or your Customer Success Manager.

## Reporting a Security Issue

If you discover a potential security vulnerability in VISO TRUST, please report it responsibly to [support@visotrust.com](mailto:support@visotrust.com). We take security reports seriously and will respond promptly.
