Platform Criteria 3: Compliances

ApplicationVisual One Intelligence (VisualOne / VSI)
Platform version referencedv6.0.0.1
CriterionCompliances, recognized certifications and attestations held by the platform
Source basisVisualOne reference documentation (VSI Virtualization Reporting User Guide, Section 9: Security, Privacy, and Data Retention)

Certifications and attestations

StandardStatusDetail
SOC 2 Type IICompliantVisual One Intelligence is compliant with SOC 2 Type II standards and completed a SOC 2 Type II audit in 2024

Supporting control environment

The controls below are documented platform behaviours that underpin the certification above and support the data protection, access control, and data lifecycle requirements common to these standards.

Authentication and access control

ControlImplementation
Encrypted authenticationVSI uses encrypted authentication and secure data handling practices
Single Sign-OnThe platform can support SSO where an organization uses it
Passwordless authenticationSupported by the platform
Least privilegeDocumented best practice for collector permissions is least privilege, with read-only access often sufficient for data collection
Alternative credential handlingSSH key authentication is supported as an alternative to stored username/password credentials for device collection
Credential state trackingCollection device records carry a Password Removed state field, making credential handling status visible in the device inventory
Controlled accessControlled access to customer data is a documented practice; administrative configuration screens (Operating Cost, Collection Devices, VM Right-Sizing) are separated from the read-oriented reporting menu
Tenant separationA Change Client selector and dedicated Clients screen scope a session to a single organization or tenant

Data protection

ControlImplementation
Encryption in transitDocumented as a platform practice
Encryption at restDocumented as a platform practice
Secure data handlingDocumented as a platform practice alongside encrypted authentication
Non-intrusive collectionData collection is agentless and reads configuration files and instrumentation rather than deploying workload-intensive agents onto production systems

Privacy and personal data

ControlImplementation
PII minimization in reportingDevice Name and Display Name fields are rendered with PII eliminated in the documented storage reporting output
Purpose-scoped collectionCollection is scoped to infrastructure configuration, capacity, performance, and cost telemetry, configured per device by an administrator

Data retention and deletion

ControlImplementation
Retention during serviceCustomer data is retained while the account is active
Deletion on terminationWhere no contract terms apply, data is deleted within 90 days of account closure, or sooner if requested
Archive optionCustomers have the option to archive data prior to deletion
Point-in-time recordThe Collection Date snapshot model preserves an auditable record of estate state on any prior collection date

Auditability and change control

ControlImplementation
Audit trail for findingsHealth alerts carry an acknowledged/unacknowledged state per record, producing an auditable disposition history
Incident escalation recordServiceNow integration creates or links incident tickets directly from alerts, placing risk items in the enterprise incident management record
Financial audit supportThe documented financial compliance workflow produces a fixed asset schedule, reconciles it to the general ledger, provides it to external auditors, and archives it for audit trail
Change-controlled remediationDocumented control points require validating orphaned resources against change records and retention policies before deletion, and coordinating right-sizing changes with change management windows and application owners
Configuration source of truthCost assumptions are held on an admin-only Operating Cost settings screen, separating who may change costing inputs from who consumes the resulting reports
Destructive action gatingCollection device removal and bulk update require explicit row selection before action

Summary

ItemPosition
SOC 2 Type IICompliant; audit completed 2024
Control environmentEncrypted authentication, SSO and passwordless support, encryption in transit and at rest, least-privilege read-only collection, SSH key auth, PII minimization in reporting, defined 90-day post-termination deletion with archive option, tenant separation, admin-scoped configuration, and auditable alert disposition and financial reconciliation workflows

Last updated: August 12, 2026