# Platform Criteria 3: Compliances | **Application** | Visual One Intelligence (VisualOne / VSI) | | --- | --- | | **Platform version referenced** | v6.0.0.1 | | **Criterion** | Compliances, recognized certifications and attestations held by the platform | | **Source basis** | VisualOne reference documentation (VSI Virtualization Reporting User Guide, Section 9: Security, Privacy, and Data Retention) | ## Certifications and attestations | **Standard** | **Status** | **Detail** | | --- | --- | --- | | **SOC 2 Type II** | **Compliant** | Visual One Intelligence is compliant with SOC 2 Type II standards and completed a SOC 2 Type II audit in **2024** | ## Supporting control environment The controls below are documented platform behaviours that underpin the certification above and support the data protection, access control, and data lifecycle requirements common to these standards. ### Authentication and access control | **Control** | **Implementation** | | --- | --- | | **Encrypted authentication** | VSI uses encrypted authentication and secure data handling practices | | **Single Sign-On** | The platform can support SSO where an organization uses it | | **Passwordless authentication** | Supported by the platform | | **Least privilege** | Documented best practice for collector permissions is least privilege, with read-only access often sufficient for data collection | | **Alternative credential handling** | SSH key authentication is supported as an alternative to stored username/password credentials for device collection | | **Credential state tracking** | Collection device records carry a Password Removed state field, making credential handling status visible in the device inventory | | **Controlled access** | Controlled access to customer data is a documented practice; administrative configuration screens (Operating Cost, Collection Devices, VM Right-Sizing) are separated from the read-oriented reporting menu | | **Tenant separation** | A Change Client selector and dedicated Clients screen scope a session to a single organization or tenant | ### Data protection | **Control** | **Implementation** | | --- | --- | | **Encryption in transit** | Documented as a platform practice | | **Encryption at rest** | Documented as a platform practice | | **Secure data handling** | Documented as a platform practice alongside encrypted authentication | | **Non-intrusive collection** | Data collection is agentless and reads configuration files and instrumentation rather than deploying workload-intensive agents onto production systems | ### Privacy and personal data | **Control** | **Implementation** | | --- | --- | | **PII minimization in reporting** | Device Name and Display Name fields are rendered with PII eliminated in the documented storage reporting output | | **Purpose-scoped collection** | Collection is scoped to infrastructure configuration, capacity, performance, and cost telemetry, configured per device by an administrator | ### Data retention and deletion | **Control** | **Implementation** | | --- | --- | | **Retention during service** | Customer data is retained while the account is active | | **Deletion on termination** | Where no contract terms apply, data is deleted within **90 days of account closure**, or sooner if requested | | **Archive option** | Customers have the option to archive data prior to deletion | | **Point-in-time record** | The Collection Date snapshot model preserves an auditable record of estate state on any prior collection date | ### Auditability and change control | **Control** | **Implementation** | | --- | --- | | **Audit trail for findings** | Health alerts carry an acknowledged/unacknowledged state per record, producing an auditable disposition history | | **Incident escalation record** | ServiceNow integration creates or links incident tickets directly from alerts, placing risk items in the enterprise incident management record | | **Financial audit support** | The documented financial compliance workflow produces a fixed asset schedule, reconciles it to the general ledger, provides it to external auditors, and archives it for audit trail | | **Change-controlled remediation** | Documented control points require validating orphaned resources against change records and retention policies before deletion, and coordinating right-sizing changes with change management windows and application owners | | **Configuration source of truth** | Cost assumptions are held on an admin-only Operating Cost settings screen, separating who may change costing inputs from who consumes the resulting reports | | **Destructive action gating** | Collection device removal and bulk update require explicit row selection before action | ## Summary | **Item** | **Position** | | --- | --- | | **SOC 2 Type II** | Compliant; audit completed 2024 | | **Control environment** | Encrypted authentication, SSO and passwordless support, encryption in transit and at rest, least-privilege read-only collection, SSH key auth, PII minimization in reporting, defined 90-day post-termination deletion with archive option, tenant separation, admin-scoped configuration, and auditable alert disposition and financial reconciliation workflows | --- Source: https://visualoneintelligence.com/docs/fof-platform-3-compliances/