Trust

Security, privacy and straight answers.

What we actually do to protect your data, what we commit to contractually, and — just as importantly — what we have not done yet. If you are running a vendor review, everything you need to start is on this page.

Last reviewed July 26, 2026

1. Certification status

Stated plainly. Visibility Zone has not completed a SOC 2 Type I or Type II audit, and holds no ISO 27001, HIPAA or PCI-DSS certification. Any vendor page that implies otherwise about us is wrong. Our infrastructure providers maintain their own independent certifications, but those are theirs — not ours, and we will not present them as if they were.

We say this on a public page rather than in the ninth email of a procurement thread because it is the question every serious security reviewer asks, and discovering an evasion at that stage costs more trust than the missing certificate ever would. If a formal attestation is a hard requirement for your organization, tell us early and we will be honest about whether we can meet your timeline.

What we can provide today: a signed Data Processing Addendum incorporating the EU Standard Contractual Clauses, a complete subprocessor list, the technical measures below, and completed security questionnaires answered accurately.

2. How your data is handled

We do not train on your content

Content you submit to the API — images, audio, text — is processed to produce your result and is not used to train general-purpose models without your written permission. This is a term of the Terms of Service and is repeated in the Privacy Policy, so it is enforceable rather than aspirational.

You are the controller, we are the processor

For everything you send us, you decide the purpose and we act on your documented instructions. Our role, obligations and your audit rights are set out in the DPA, which is incorporated automatically for every customer — you do not have to negotiate for baseline protection.

Optional model features can be switched off

Some analysis features route content to third-party model providers listed in our subprocessor disclosure. Platform customers can request that these optional features be disabled for their account, keeping processing within our own infrastructure. Ask before you integrate and we will configure it up front.

We do not sell personal information

We do not sell personal information and do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We honor Global Privacy Control signals.

3. Technical measures

These are the controls in place today. They are also the measures committed to contractually in Annex II of our DPA.

AreaControl
Encryption in transitTLS 1.2 or higher on all endpoints. Plain HTTP is rejected rather than redirected. HSTS enabled.
Encryption at restStored service data and backups are encrypted at rest.
Access controlRole-based access on the principle of least privilege. Multi-factor authentication required for administrative access. Access is reviewed when roles change.
NetworkSegmented networks, firewalled origin, edge WAF and DDoS protection. Administrative interfaces are not exposed to the public internet.
CredentialsAPI keys are stored hashed, are scoped per environment, and support zero-downtime rotation. Secrets are never committed to source control.
LoggingCentralized application and access logging with retention sufficient for incident investigation. Logs are scrubbed of request payload content.
PatchingOperating system and dependency patching on a regular cadence, with expedited handling for actively exploited vulnerabilities.
BackupsAutomated backups with periodic restore testing. Backups inherit the same encryption and access controls as production.
DevelopmentCode review before deployment, separated test and production environments and credentials, dependency vulnerability scanning.
PeopleWritten confidentiality obligations for everyone with data access, and access removal as part of offboarding.

These measures are reviewed periodically and may be updated, provided that no update reduces the overall level of protection.

4. Data location and retention

Production infrastructure runs on dedicated servers in a European data centre, with a US-headquartered CDN and security proxy handling TLS termination and edge protection globally. Some optional model-processing features are operated by US providers. Full details, including every subprocessor and its location, are on the Subprocessors page.

DataRetention
API request payloads (images, audio, text)Maximum 30 days for debugging and abuse prevention, then deleted
Indexed catalog itemsFor as long as the index exists; deleted on request or on account closure
Monitoring and platform dataFor the life of the subscription
Account and billing recordsLife of the account, then up to 7 years where tax and accounting law requires it

On termination you can export your data for 30 days, after which personal data is deleted within a further 30 days except where retention is legally required.

5. Vulnerability disclosure

If you believe you have found a security vulnerability, we want to hear about it and we will not pursue you for reporting it in good faith.

How to report

Email [email protected] with the subject line Attn: Security. Include the affected endpoint or URL, reproduction steps, and what you believe the impact is. Machine-readable contact details are published at /.well-known/security.txt.

What we commit to

  • Acknowledgement within two business days.
  • An assessment and a remediation plan within ten business days.
  • Credit in our advisory if you would like it, once a fix is deployed.

Ground rules

  • Test only against your own account and data. Do not access, modify or exfiltrate other customers' data.
  • No denial of service, no automated scanning that degrades the service, no social engineering of our staff or vendors.
  • Give us reasonable time to remediate before any public disclosure.
  • Do not test our third-party providers — report those to them directly.

We do not currently operate a paid bug bounty program. We will say so honestly rather than let researchers assume otherwise.

6. Incident response

We maintain a documented incident response process covering detection, containment, eradication, recovery and post-incident review. Where we process personal data on your behalf and become aware of a personal data breach, we notify the affected customer without undue delay and, where feasible, within 48 hours of becoming aware — including what we know about the nature of the incident, the categories and approximate volume of data involved, the likely consequences and the measures taken. Those commitments are contractual and are set out in our DPA.

Service availability and maintenance notices are published on our status page.

7. Vendor review pack

Everything a procurement or security team typically asks for, in one place:

Reviewing us as a vendor? Send your questionnaire to [email protected]. We answer every question, including the ones where the answer is "not yet."