Trust Center
Security, Privacy, and Compliance You Can Verify
VIDIZMO runs one Information Security and Product Security program across its entire platform. The job is straightforward: protect customer data, keep the service available, and keep it accurate.
Certifications and Attestations
SOC 2 Type II
Inherited through Microsoft Azure’s own attestation, not held by VIDIZMO in its own name.
CSA STAR
A cloud-specific security registration, inherited through Microsoft Azure the same way SOC 2 is.
FedRAMP High
A concrete path to FedRAMP High for VIDIZMO Products, backed by a specific implementation timeline.
Regulatory and Sector Frameworks
CJIS Security Policy
Supported across every VIDIZMO product and every deployment option, not just Azure Government Cloud.
HIPAA
VIDIZMO is not a healthcare provider. Many of our customers and use cases are in healthcare and need HIPAA compliance, and VIDIZMO provides the safeguards to get them there, across every product.
GDPR & CCPA-CPRA
How VIDIZMO supports EU data protection and California consumer privacy requirements.
PCI DSS
PCI DSS does not apply to VIDIZMO in its own right. We do not process, store, or transmit cardholder data or handle financial transactions as part of our business. Where it matters is on the customer’s side: if you’re a bank, payment processor, or any organization storing payment-related records, VIDIZMO can help you meet your own PCI DSS obligations for that data.
NIST SP 800-53
The federal security control catalog VIDIZMO supports on Azure Government Cloud deployments.
NIST AI RMF
The voluntary federal framework for managing AI risk, and how VIDIZMO’s practices map to it.
WCAG 2.2 AA & Section 508
The technical accessibility standard VIDIZMO supports across every product, and the federal regulation that requires it.
The VIDIZMO Trust Program
Data Protection & Encryption
- AES-256 encryption at rest
- TLS 1.2 minimum in transit (TLS 1.3 supported)
- Separate encryption keys per tenant, managed in Azure Key Vault and rotated biennially
- FIPS-compliant, NIST-recommended cryptography
Incident Response & Vulnerability Management
- Weekly automated vulnerability scans across apps, APIs, and cloud resources
- Quarterly independent penetration testing with retesting
- Security patches applied within 5 business days of vendor release
- Breach notification within 2 business days of confirmation
Data Residency & Deployment Options
- SaaS (shared or dedicated), on-premises, private cloud, hybrid, bring-your-own-cloud, and fully air-gapped deployment models
- Data residency options include U.S.-based data centers, Canadian data centers (dedicated SaaS), and the Europe region
- Customer-chosen geographic region available for dedicated SaaS deployments
- Air-gapped deployments run entirely on-premises with no external network access; no data leaves the environment
Access Control & Identity
- SSO, MFA, and role-based access control (least privilege)
- Zero-standing-access for VIDIZMO staff: break-glass only, time-bound, fully logged
- Tenant isolation at application, database, and storage levels
- Zero Trust architecture with geo- and IP-based restrictions
Responsible AI & Data Governance
- Customer data is never used to train AI models without explicit written consent
- Published Responsible AI Policy covering fairness, accountability, and safety
- Model inventory (“bill of models”) available under NDA
- NIST AI Risk Management Framework alignment
Business Continuity & Disaster Recovery
- Recovery Time Objective: 48 hours
- Recovery Point Objective: 24 hours
- Geo-redundant storage with automated cross-region failover
- Semi-annual disaster recovery testing
Who Owns What in a SaaS Deployment
Customer is the data Controller; VIDIZMO is the Processor; Microsoft Azure is the infrastructure sub-processor.
| Responsibility | Owner |
|---|---|
| Application/platform security, secure SDLC, tenant isolation | VIDIZMO |
| Uptime SLA, vulnerability scanning, penetration testing | VIDIZMO |
| Incident response, breach notification, encryption, secure deletion | VIDIZMO |
| Data classification, content and metadata quality | Customer |
| Retention policies and legal holds | Customer |
| User and role administration, SSO/MFA/IdP policy | Customer |
| Audit log review, export and eDiscovery | Customer |
FAQ
Trust and compliance, asked and answered
What certifications does VIDIZMO hold?
Is VIDIZMO FedRAMP authorized?
Does VIDIZMO support HIPAA and GDPR requirements?
How does VIDIZMO protect customer data?
Do these certifications apply across all VIDIZMO products?
Who manages VIDIZMO's security program?
Need documentation for a security review?
We can provide the documentation your review requires. For anything else, our security team is ready to help.