Trust Center

Security, Privacy, and Compliance You Can Verify

VIDIZMO runs one Information Security and Product Security program across its entire platform. The job is straightforward: protect customer data, keep the service available, and keep it accurate.

Certifications and Attestations

ISO/IEC 27001:2022

Certified to ISO/IEC 27001:2022 under UKAS accreditation.

SOC 2 Type II

Inherited through Microsoft Azure’s own attestation, not held by VIDIZMO in its own name.

CSA STAR

A cloud-specific security registration, inherited through Microsoft Azure the same way SOC 2 is.

FedRAMP High

A concrete path to FedRAMP High for VIDIZMO Products, backed by a specific implementation timeline.

Regulatory and Sector Frameworks

CJIS Security Policy

Supported across every VIDIZMO product and every deployment option, not just Azure Government Cloud.

HIPAA

VIDIZMO is not a healthcare provider. Many of our customers and use cases are in healthcare and need HIPAA compliance, and VIDIZMO provides the safeguards to get them there, across every product.

GDPR & CCPA-CPRA

How VIDIZMO supports EU data protection and California consumer privacy requirements.

PCI DSS

PCI DSS does not apply to VIDIZMO in its own right. We do not process, store, or transmit cardholder data or handle financial transactions as part of our business. Where it matters is on the customer’s side: if you’re a bank, payment processor, or any organization storing payment-related records, VIDIZMO can help you meet your own PCI DSS obligations for that data.

NIST SP 800-53

The federal security control catalog VIDIZMO supports on Azure Government Cloud deployments.

NIST AI RMF

The voluntary federal framework for managing AI risk, and how VIDIZMO’s practices map to it.

WCAG 2.2 AA & Section 508

The technical accessibility standard VIDIZMO supports across every product, and the federal regulation that requires it.

The VIDIZMO Trust Program

Data Protection & Encryption

  • AES-256 encryption at rest
  • TLS 1.2 minimum in transit (TLS 1.3 supported)
  • Separate encryption keys per tenant, managed in Azure Key Vault and rotated biennially
  • FIPS-compliant, NIST-recommended cryptography

Learn More

Incident Response & Vulnerability Management

  • Weekly automated vulnerability scans across apps, APIs, and cloud resources
  • Quarterly independent penetration testing with retesting
  • Security patches applied within 5 business days of vendor release
  • Breach notification within 2 business days of confirmation

Learn More

Data Residency & Deployment Options

  • SaaS (shared or dedicated), on-premises, private cloud, hybrid, bring-your-own-cloud, and fully air-gapped deployment models
  • Data residency options include U.S.-based data centers, Canadian data centers (dedicated SaaS), and the Europe region
  • Customer-chosen geographic region available for dedicated SaaS deployments
  • Air-gapped deployments run entirely on-premises with no external network access; no data leaves the environment

Learn More

Access Control & Identity

  • SSO, MFA, and role-based access control (least privilege)
  • Zero-standing-access for VIDIZMO staff: break-glass only, time-bound, fully logged
  • Tenant isolation at application, database, and storage levels
  • Zero Trust architecture with geo- and IP-based restrictions

Learn More

Responsible AI & Data Governance

  • Customer data is never used to train AI models without explicit written consent
  • Published Responsible AI Policy covering fairness, accountability, and safety
  • Model inventory (“bill of models”) available under NDA
  • NIST AI Risk Management Framework alignment

Learn More

Business Continuity & Disaster Recovery

  • Recovery Time Objective: 48 hours
  • Recovery Point Objective: 24 hours
  • Geo-redundant storage with automated cross-region failover
  • Semi-annual disaster recovery testing

Learn More

Who Owns What in a SaaS Deployment

Customer is the data Controller; VIDIZMO is the Processor; Microsoft Azure is the infrastructure sub-processor.

ResponsibilityOwner
Application/platform security, secure SDLC, tenant isolationVIDIZMO
Uptime SLA, vulnerability scanning, penetration testingVIDIZMO
Incident response, breach notification, encryption, secure deletionVIDIZMO
Data classification, content and metadata qualityCustomer
Retention policies and legal holdsCustomer
User and role administration, SSO/MFA/IdP policyCustomer
Audit log review, export and eDiscoveryCustomer

FAQ

Trust and compliance, asked and answered

What certifications does VIDIZMO hold?

VIDIZMO holds ISO/IEC 27001:2022 certification directly for its information security management. Other frameworks, including SOC 2 Type II, FedRAMP High, and CJIS, are supported through VIDIZMO's deployment on Microsoft Azure and Azure Government Cloud rather than as separate VIDIZMO-held certifications.

Is VIDIZMO FedRAMP authorized?

VIDIZMO does not hold its own FedRAMP authorization. The platform is built to align with NIST SP 800-53 and is deployable on FedRAMP High-authorized infrastructure (Azure Government Cloud, or via Project Hosts), which agencies can use to meet their own FedRAMP requirements.

Does VIDIZMO support HIPAA and GDPR requirements?

Yes. VIDIZMO's data protection, redaction, and anonymization capabilities are built to support customers' HIPAA obligations, with a BAA available case-by-case, and in-application deletion/purge features to support GDPR data privacy requirements. These are customer compliance obligations that VIDIZMO's controls help satisfy, not certifications VIDIZMO itself holds.

How does VIDIZMO protect customer data?

Data is encrypted at rest with AES-256 and in transit with TLS (1.2 minimum, 1.3 supported), with encryption keys managed and rotated annually via Azure Key Vault. Access is controlled through MFA, SSO, and role-based access control on the principle of least privilege.

Do these certifications apply across all VIDIZMO products?

Yes, ISO 27001, CJIS alignment, FedRAMP High deployability, HIPAA support, and GDPR support all apply consistently across DEMS, EnterpriseTube, Redactor, AI Intelligence Hub, and AI Live Insight.

Who manages VIDIZMO's security program?

Dedicated Information Security and Product Security teams run VIDIZMO's security program, focused on defining controls, operating a security framework, and continuous risk management, testing, and improvement.

Need documentation for a security review?

We can provide the documentation your review requires. For anything else, our security team is ready to help.