Trust Center

Security, Privacy, and Compliance You Can Verify

VIDIZMO runs one Information Security and Product Security program across its entire platform. The job is straightforward: protect customer data, keep the service available, and keep it accurate.

Certifications and Attestations

ISO/IEC 27001:2022

Certified to ISO/IEC 27001:2022 under UKAS accreditation.

SOC 2 Type II

Inherited through Microsoft Azure’s own attestation, not held by VIDIZMO in its own name.

CSA STAR

A cloud-specific security registration, inherited through Microsoft Azure the same way SOC 2 is.

FedRAMP High

A concrete path to FedRAMP High for VIDIZMO Products, backed by a specific implementation timeline.

Regulatory and Sector Frameworks

CJIS Security Policy

Supported across every VIDIZMO product and every deployment option, not just Azure Government Cloud.

HIPAA

VIDIZMO is not a healthcare provider. Many of our customers and use cases are in healthcare and need HIPAA compliance, and VIDIZMO provides the safeguards to get them there, across every product.

GDPR & CCPA-CPRA

How VIDIZMO supports EU data protection and California consumer privacy requirements.

PCI DSS

PCI DSS does not apply to VIDIZMO in its own right. We do not process, store, or transmit cardholder data or handle financial transactions as part of our business. Where it matters is on the customer’s side: if you’re a bank, payment processor, or any organization storing payment-related records, VIDIZMO can help you meet your own PCI DSS obligations for that data.

NIST SP 800-53

The federal security control catalog VIDIZMO supports on Azure Government Cloud deployments.

FIPS 140-3

The U.S. government standard for validated cryptographic modules; VIDIZMO applies FIPS 140-3 validated cryptography for data at rest and in transit.

NIST AI RMF

The voluntary federal framework for managing AI risk, and how VIDIZMO’s practices map to it.

WCAG 2.2 AA & Section 508

The technical accessibility standard VIDIZMO supports across every product, and the federal regulation that requires it.

The VIDIZMO Trust Program

Data Protection & Encryption

  • AES-256 encryption at rest
  • TLS 1.2 minimum in transit (TLS 1.3 supported)
  • Separate encryption keys per tenant, managed in Azure Key Vault and rotated biennially
  • FIPS-compliant, NIST-recommended cryptography

Learn More

Incident Response & Vulnerability Management

  • Weekly automated vulnerability scans across apps, APIs, and cloud resources
  • Quarterly independent penetration testing with retesting
  • Security patches applied within 5 business days of vendor release
  • Breach notification within 2 business days of confirmation

Learn More

Data Residency & Deployment Options

  • SaaS (shared or dedicated), on-premises, private cloud, hybrid, bring-your-own-cloud, and fully air-gapped deployment models
  • Data residency options include U.S.-based data centers, Canadian data centers (dedicated SaaS), and the Europe region
  • Customer-chosen geographic region available for dedicated SaaS deployments
  • Air-gapped deployments run entirely on-premises with no external network access; no data leaves the environment

Learn More

Access Control & Identity

  • SSO, MFA, and role-based access control (least privilege)
  • Zero-standing-access for VIDIZMO staff: break-glass only, time-bound, fully logged
  • Tenant isolation at application, database, and storage levels
  • Zero Trust architecture with geo- and IP-based restrictions

Learn More

Responsible AI & Data Governance

  • Customer data is never used to train AI models without explicit written consent
  • Published Responsible AI Policy covering fairness, accountability, and safety
  • Model inventory (“bill of models”) available under NDA
  • NIST AI Risk Management Framework alignment

Learn More

Business Continuity & Disaster Recovery

  • Recovery Time Objective: 48 hours
  • Recovery Point Objective: 24 hours
  • Geo-redundant storage with automated cross-region failover
  • Semi-annual disaster recovery testing

Learn More

Who Owns What in a SaaS Deployment

Customer is the data Controller; VIDIZMO is the Processor; Microsoft Azure is the infrastructure sub-processor.

ResponsibilityOwner
Application/platform security, secure SDLC, tenant isolationVIDIZMO
Uptime SLA, vulnerability scanning, penetration testingVIDIZMO
Incident response, breach notification, encryption, secure deletionVIDIZMO
Data classification, content and metadata qualityCustomer
Retention policies and legal holdsCustomer
User and role administration, SSO/MFA/IdP policyCustomer
Audit log review, export and eDiscoveryCustomer

Need documentation for a security review?

We can provide the documentation your review requires. For anything else, our security team is ready to help.