Last updated September 16, 2026
Visualping Trust Center
Enterprise-grade security, compliance and privacy. Here’s how we protect what you share with us, and how to verify it yourself.
- SOC 2 audit underway
- DPA on every business plan
Compliance
Our current certifications and the standards we align to. Reports are available on request under NDA.
SOC 2 Type I
Point-in-time assessment of our security controls, in preparation with an independent CPA firm. Report expected Q4 2026.
SOC 2 Type II
Ongoing assessment across an observation window. Planned following our Type I report.
GDPR
We process personal data in line with the EU General Data Protection Regulation. DPA available on request.
CCPA
We honor privacy rights under the California Consumer Privacy Act.
How we protect your data
The security practices behind Visualping, grouped by the areas our SOC 2 program covers.
Access control
MFA enforced everywhere, SSO where available, least-privilege role-based access, and quarterly access reviews.
Encryption
Data encrypted in transit (TLS) and at rest, with full-disk encryption on all company devices. Secrets managed through our cloud provider's key management.
Monitoring & logging
Production activity is logged and monitored with alerting on anomalous behavior, endpoint detection and response on all devices, and activity logs retained for 12 months.
Change management
All changes go through code review and approval, with separation of development and production environments.
Resilience
Automated, encrypted, immutable backups with restore testing, plus a documented incident response and business continuity plan with a 4-hour recovery time objective.
People & training
Background checks where lawful, signed confidentiality agreements, and security awareness training for all staff.
Subprocessors
Third parties that may process customer data on our behalf.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage, email delivery | United States |
| OpenAI | AI change analysis & chat assistant | United States |
| Anthropic | AI change analysis & chat assistant | United States |
| AI change analysis (Gemini), chat assistant & reCAPTCHA | United States | |
| Microsoft Azure | AI change analysis | United States |
| Stripe | Billing & payments | United States |
| PayPal | Payments | United States |
| Front | Customer support | United States |
| HubSpot | CRM & marketing forms | United States |
| FormCrafts | Contact & demo request forms | Germany |
| Mixpanel | Product analytics | United States |
| Honeycomb | Application observability | United States |
For your security review
Get the documents your team will ask for
Security whitepaper, Data Processing Agreement and our full Risk Ledger security assessment with supporting evidence — shared under NDA, usually within one business day.
- Security whitepaper
- Data Processing Agreement (DPA)
- Risk Ledger security assessment
Request access
FAQ
What security teams ask before they sign
Where is our data stored?
In AWS United States regions (us-west-2, Oregon). Backups are encrypted, immutable and tested regularly.
Do you access content behind our logins?
Only if you configure credentialed monitoring. Credentials are encrypted and used solely to load the page you specify.
Can you monitor sites on our private network?
No. Visualping is a hosted service: our capture workers run in AWS and can only reach URLs that are publicly routable from the internet. A monitor pointed at an intranet hostname or a private IP address is accepted by the form, but its checks will fail. There is no on-premise or self-hosted deployment, and no agent that runs inside your network. Pages that are publicly reachable but sit behind a login are supported through credentialed monitoring.
Is our data used to train AI models?
No. Client data processed by AI-powered features is never used for model training, and is discarded once processing completes.
When will SOC 2 be complete?
The Type I assessment is underway with an independent CPA firm and the report is expected Q4 2026, with the Type II audit to follow. Reports will be shared under NDA.
Will you complete our security questionnaire?
Yes — SIG and SIG Lite, CAIQ, and your own custom questionnaire. Email it to [email protected]. Our Risk Ledger security assessment is already complete and covers the same ground, so request that as well if your review needs answers before the questionnaire comes back.
Who are your subprocessors?
AWS for hosting and email, Stripe and PayPal for payments, OpenAI, Anthropic, Google and Microsoft Azure for AI features, and a small set of support, analytics and monitoring vendors — the full list with purposes and locations is in the subprocessors section above.
Who owns security at Visualping?
We have an appointed security lead and a nominated Data Protection Officer, with security policies reviewed and approved by senior management annually.
How do I report a vulnerability?
Email [email protected]. We acknowledge every report within one business day.
Stay in the know — securely
Questions from your security team? We’ll help you fill in the questionnaire, usually within a day.