1. Certification status
Stated plainly. Visibility Zone has not completed a SOC 2 Type I or Type II audit, and holds no ISO 27001, HIPAA or PCI-DSS certification. Any vendor page that implies otherwise about us is wrong. Our infrastructure providers maintain their own independent certifications, but those are theirs — not ours, and we will not present them as if they were.
We say this on a public page rather than in the ninth email of a procurement thread because it is the question every serious security reviewer asks, and discovering an evasion at that stage costs more trust than the missing certificate ever would. If a formal attestation is a hard requirement for your organization, tell us early and we will be honest about whether we can meet your timeline.
What we can provide today: a signed Data Processing Addendum incorporating the EU Standard Contractual Clauses, a complete subprocessor list, the technical measures below, and completed security questionnaires answered accurately.
2. How your data is handled
We do not train on your content
Content you submit to the API — images, audio, text — is processed to produce your result and is not used to train general-purpose models without your written permission. This is a term of the Terms of Service and is repeated in the Privacy Policy, so it is enforceable rather than aspirational.
You are the controller, we are the processor
For everything you send us, you decide the purpose and we act on your documented instructions. Our role, obligations and your audit rights are set out in the DPA, which is incorporated automatically for every customer — you do not have to negotiate for baseline protection.
Optional model features can be switched off
Some analysis features route content to third-party model providers listed in our subprocessor disclosure. Platform customers can request that these optional features be disabled for their account, keeping processing within our own infrastructure. Ask before you integrate and we will configure it up front.
We do not sell personal information
We do not sell personal information and do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We honor Global Privacy Control signals.
3. Technical measures
These are the controls in place today. They are also the measures committed to contractually in Annex II of our DPA.
| Area | Control |
|---|---|
| Encryption in transit | TLS 1.2 or higher on all endpoints. Plain HTTP is rejected rather than redirected. HSTS enabled. |
| Encryption at rest | Stored service data and backups are encrypted at rest. |
| Access control | Role-based access on the principle of least privilege. Multi-factor authentication required for administrative access. Access is reviewed when roles change. |
| Network | Segmented networks, firewalled origin, edge WAF and DDoS protection. Administrative interfaces are not exposed to the public internet. |
| Credentials | API keys are stored hashed, are scoped per environment, and support zero-downtime rotation. Secrets are never committed to source control. |
| Logging | Centralized application and access logging with retention sufficient for incident investigation. Logs are scrubbed of request payload content. |
| Patching | Operating system and dependency patching on a regular cadence, with expedited handling for actively exploited vulnerabilities. |
| Backups | Automated backups with periodic restore testing. Backups inherit the same encryption and access controls as production. |
| Development | Code review before deployment, separated test and production environments and credentials, dependency vulnerability scanning. |
| People | Written confidentiality obligations for everyone with data access, and access removal as part of offboarding. |
These measures are reviewed periodically and may be updated, provided that no update reduces the overall level of protection.
4. Data location and retention
Production infrastructure runs on dedicated servers in a European data centre, with a US-headquartered CDN and security proxy handling TLS termination and edge protection globally. Some optional model-processing features are operated by US providers. Full details, including every subprocessor and its location, are on the Subprocessors page.
| Data | Retention |
|---|---|
| API request payloads (images, audio, text) | Maximum 30 days for debugging and abuse prevention, then deleted |
| Indexed catalog items | For as long as the index exists; deleted on request or on account closure |
| Monitoring and platform data | For the life of the subscription |
| Account and billing records | Life of the account, then up to 7 years where tax and accounting law requires it |
On termination you can export your data for 30 days, after which personal data is deleted within a further 30 days except where retention is legally required.
5. Vulnerability disclosure
If you believe you have found a security vulnerability, we want to hear about it and we will not pursue you for reporting it in good faith.
How to report
Email [email protected] with the subject line Attn: Security. Include the affected endpoint or URL, reproduction steps, and what you believe the impact is. Machine-readable contact details are published at /.well-known/security.txt.
What we commit to
- Acknowledgement within two business days.
- An assessment and a remediation plan within ten business days.
- Credit in our advisory if you would like it, once a fix is deployed.
Ground rules
- Test only against your own account and data. Do not access, modify or exfiltrate other customers' data.
- No denial of service, no automated scanning that degrades the service, no social engineering of our staff or vendors.
- Give us reasonable time to remediate before any public disclosure.
- Do not test our third-party providers — report those to them directly.
We do not currently operate a paid bug bounty program. We will say so honestly rather than let researchers assume otherwise.
6. Incident response
We maintain a documented incident response process covering detection, containment, eradication, recovery and post-incident review. Where we process personal data on your behalf and become aware of a personal data breach, we notify the affected customer without undue delay and, where feasible, within 48 hours of becoming aware — including what we know about the nature of the incident, the categories and approximate volume of data involved, the likely consequences and the measures taken. Those commitments are contractual and are set out in our DPA.
Service availability and maintenance notices are published on our status page.
7. Vendor review pack
Everything a procurement or security team typically asks for, in one place:
- Data Processing Addendum — GDPR Article 28 terms, SCCs, Annex II technical measures
- Subprocessor list — every vendor, purpose, data category and location
- Privacy Policy — GDPR, UK GDPR, CCPA/CPRA and other US state law disclosures
- Terms of Service and Acceptable Use Policy
- Completed security questionnaires — request one with the subject line Attn: Security
Reviewing us as a vendor? Send your questionnaire to [email protected]. We answer every question, including the ones where the answer is "not yet."