Last updated September 16, 2026

Visualping Trust Center

Enterprise-grade security, compliance and privacy. Here’s how we protect what you share with us, and how to verify it yourself.

  • SOC 2 audit underway
  • DPA on every business plan
Our compliance postureIn progressSOC 2GDPRCCPAPIPEDA

Compliance

Our current certifications and the standards we align to. Reports are available on request under NDA.

In progress

SOC 2 Type I

Point-in-time assessment of our security controls, in preparation with an independent CPA firm. Report expected Q4 2026.

Planned

SOC 2 Type II

Ongoing assessment across an observation window. Planned following our Type I report.

Aligned

GDPR

We process personal data in line with the EU General Data Protection Regulation. DPA available on request.

Aligned

CCPA

We honor privacy rights under the California Consumer Privacy Act.

How we protect your data

The security practices behind Visualping, grouped by the areas our SOC 2 program covers.

Access control

MFA enforced everywhere, SSO where available, least-privilege role-based access, and quarterly access reviews.

Encryption

Data encrypted in transit (TLS) and at rest, with full-disk encryption on all company devices. Secrets managed through our cloud provider's key management.

Monitoring & logging

Production activity is logged and monitored with alerting on anomalous behavior, endpoint detection and response on all devices, and activity logs retained for 12 months.

Change management

All changes go through code review and approval, with separation of development and production environments.

Resilience

Automated, encrypted, immutable backups with restore testing, plus a documented incident response and business continuity plan with a 4-hour recovery time objective.

People & training

Background checks where lawful, signed confidentiality agreements, and security awareness training for all staff.

Subprocessors

Third parties that may process customer data on our behalf.

SubprocessorPurposeLocation
Amazon Web ServicesCloud hosting, storage, email deliveryUnited States
OpenAIAI change analysis & chat assistantUnited States
AnthropicAI change analysis & chat assistantUnited States
GoogleAI change analysis (Gemini), chat assistant & reCAPTCHAUnited States
Microsoft AzureAI change analysisUnited States
StripeBilling & paymentsUnited States
PayPalPaymentsUnited States
FrontCustomer supportUnited States
HubSpotCRM & marketing formsUnited States
FormCraftsContact & demo request formsGermany
MixpanelProduct analyticsUnited States
HoneycombApplication observabilityUnited States

For your security review

Get the documents your team will ask for

Security whitepaper, Data Processing Agreement and our full Risk Ledger security assessment with supporting evidence — shared under NDA, usually within one business day.

  • Security whitepaper
  • Data Processing Agreement (DPA)
  • Risk Ledger security assessment

Request access

FAQ

What security teams ask before they sign

Where is our data stored?

In AWS United States regions (us-west-2, Oregon). Backups are encrypted, immutable and tested regularly.

Do you access content behind our logins?

Only if you configure credentialed monitoring. Credentials are encrypted and used solely to load the page you specify.

Can you monitor sites on our private network?

No. Visualping is a hosted service: our capture workers run in AWS and can only reach URLs that are publicly routable from the internet. A monitor pointed at an intranet hostname or a private IP address is accepted by the form, but its checks will fail. There is no on-premise or self-hosted deployment, and no agent that runs inside your network. Pages that are publicly reachable but sit behind a login are supported through credentialed monitoring.

Is our data used to train AI models?

No. Client data processed by AI-powered features is never used for model training, and is discarded once processing completes.

When will SOC 2 be complete?

The Type I assessment is underway with an independent CPA firm and the report is expected Q4 2026, with the Type II audit to follow. Reports will be shared under NDA.

Will you complete our security questionnaire?

Yes — SIG and SIG Lite, CAIQ, and your own custom questionnaire. Email it to security@visualping.io. Our Risk Ledger security assessment is already complete and covers the same ground, so request that as well if your review needs answers before the questionnaire comes back.

Who are your subprocessors?

AWS for hosting and email, Stripe and PayPal for payments, OpenAI, Anthropic, Google and Microsoft Azure for AI features, and a small set of support, analytics and monitoring vendors — the full list with purposes and locations is in the subprocessors section above.

Who owns security at Visualping?

We have an appointed security lead and a nominated Data Protection Officer, with security policies reviewed and approved by senior management annually.

How do I report a vulnerability?

Email security@visualping.io. We acknowledge every report within one business day.

Stay in the know — securely

Questions from your security team? We’ll help you fill in the questionnaire, usually within a day.