Compliances, recognized certifications and attestations held by the platform
Source basis
VisualOne reference documentation (VSI Virtualization Reporting User Guide, Section 9: Security, Privacy, and Data Retention)
Certifications and attestations
Standard
Status
Detail
SOC 2 Type II
Compliant
Visual One Intelligence is compliant with SOC 2 Type II standards and completed a SOC 2 Type II audit in 2024
Supporting control environment
The controls below are documented platform behaviours that underpin the certification above and support the data protection, access control, and data lifecycle requirements common to these standards.
Authentication and access control
Control
Implementation
Encrypted authentication
VSI uses encrypted authentication and secure data handling practices
Single Sign-On
The platform can support SSO where an organization uses it
Passwordless authentication
Supported by the platform
Least privilege
Documented best practice for collector permissions is least privilege, with read-only access often sufficient for data collection
Alternative credential handling
SSH key authentication is supported as an alternative to stored username/password credentials for device collection
Credential state tracking
Collection device records carry a Password Removed state field, making credential handling status visible in the device inventory
Controlled access
Controlled access to customer data is a documented practice; administrative configuration screens (Operating Cost, Collection Devices, VM Right-Sizing) are separated from the read-oriented reporting menu
Tenant separation
A Change Client selector and dedicated Clients screen scope a session to a single organization or tenant
Data protection
Control
Implementation
Encryption in transit
Documented as a platform practice
Encryption at rest
Documented as a platform practice
Secure data handling
Documented as a platform practice alongside encrypted authentication
Non-intrusive collection
Data collection is agentless and reads configuration files and instrumentation rather than deploying workload-intensive agents onto production systems
Privacy and personal data
Control
Implementation
PII minimization in reporting
Device Name and Display Name fields are rendered with PII eliminated in the documented storage reporting output
Purpose-scoped collection
Collection is scoped to infrastructure configuration, capacity, performance, and cost telemetry, configured per device by an administrator
Data retention and deletion
Control
Implementation
Retention during service
Customer data is retained while the account is active
Deletion on termination
Where no contract terms apply, data is deleted within 90 days of account closure, or sooner if requested
Archive option
Customers have the option to archive data prior to deletion
Point-in-time record
The Collection Date snapshot model preserves an auditable record of estate state on any prior collection date
Auditability and change control
Control
Implementation
Audit trail for findings
Health alerts carry an acknowledged/unacknowledged state per record, producing an auditable disposition history
Incident escalation record
ServiceNow integration creates or links incident tickets directly from alerts, placing risk items in the enterprise incident management record
Financial audit support
The documented financial compliance workflow produces a fixed asset schedule, reconciles it to the general ledger, provides it to external auditors, and archives it for audit trail
Change-controlled remediation
Documented control points require validating orphaned resources against change records and retention policies before deletion, and coordinating right-sizing changes with change management windows and application owners
Configuration source of truth
Cost assumptions are held on an admin-only Operating Cost settings screen, separating who may change costing inputs from who consumes the resulting reports
Destructive action gating
Collection device removal and bulk update require explicit row selection before action
Summary
Item
Position
SOC 2 Type II
Compliant; audit completed 2024
Control environment
Encrypted authentication, SSO and passwordless support, encryption in transit and at rest, least-privilege read-only collection, SSH key auth, PII minimization in reporting, defined 90-day post-termination deletion with archive option, tenant separation, admin-scoped configuration, and auditable alert disposition and financial reconciliation workflows