Trust Center · Last updated August 6, 2026
Teams at 85% of Fortune 500 companies rely on Visualping to watch the web for them. This page explains how we protect what they share with us — and how to verify it yourself.
Our current certifications and the standards we align to. Reports are available on request under NDA.
Point-in-time assessment of our security controls, in preparation with an independent CPA firm. Report expected Q4 2026.
Ongoing assessment across an observation window. Planned following our Type I report.
We process personal data in line with the EU General Data Protection Regulation. DPA available on request.
We honor privacy rights under the California Consumer Privacy Act.
The security practices behind Visualping, grouped by the areas our SOC 2 program covers.
MFA enforced everywhere, SSO where available, least-privilege role-based access, and quarterly access reviews.
Data encrypted in transit (TLS) and at rest, with full-disk encryption on all company devices. Secrets managed through our cloud provider's key management.
Production activity is logged and monitored with alerting on anomalous behavior, endpoint detection and response on all devices, and activity logs retained for 12 months.
All changes go through code review and approval, with separation of development and production environments.
Automated, encrypted, immutable backups with restore testing, plus a documented incident response and business continuity plan with a 4-hour recovery time objective.
Background checks where lawful, signed confidentiality agreements, and security awareness training for all staff.
Third parties that may process customer data on our behalf.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage, email delivery | United States |
| OpenAI | AI change analysis & chat assistant | United States |
| Anthropic | AI change analysis & chat assistant | United States |
| AI change analysis (Gemini), chat assistant & reCAPTCHA | United States | |
| Microsoft Azure | AI change analysis | United States |
| Stripe | Billing & payments | United States |
| PayPal | Payments | United States |
| Front | Customer support | United States |
| HubSpot | CRM & marketing forms | United States |
| FormCrafts | Contact & demo request forms | Germany |
| Mixpanel | Product analytics | United States |
| Honeycomb | Application observability | United States |
| IPRoyal | Proxy network for page monitoring | Lithuania |
| Decodo | Proxy network for page monitoring | Lithuania |
For your security review
Security whitepaper, Data Processing Agreement and our full Risk Ledger security assessment with supporting evidence — shared under NDA, usually within one business day.
FAQ
In AWS United States regions (us-west-2, Oregon). Backups are encrypted, immutable and tested regularly.
Only if you configure credentialed monitoring. Credentials are encrypted and used solely to load the page you specify.
No. Client data processed by AI-powered features is never used for model training, and is discarded once processing completes.
The Type I assessment is underway with an independent CPA firm and the report is expected Q4 2026, with the Type II audit to follow. Reports will be shared under NDA.
AWS for hosting and email, Stripe and PayPal for payments, OpenAI, Anthropic, Google and Microsoft Azure for AI features, and a small set of support, analytics and monitoring vendors — the full list with purposes and locations is in the subprocessors section above.
We have an appointed security lead and a nominated Data Protection Officer, with security policies reviewed and approved by senior management annually.
Email security@visualping.io. We acknowledge every report within one business day.
Questions from your security team? We’ll help you fill in the questionnaire, usually within a day.