Trust Center / Access Control & Identity

Access Control & Identity

Who can get in, what they can see, and how VIDIZMO keeps its own staff out of your data by default.

What It Is

Access control and identity management cover how a system verifies who a user is and limits what they can do once they’re in. For a platform holding evidence, video, and sensitive records, this is usually the first thing a security reviewer checks.

How VIDIZMO Implements It

  • Single Sign-On, Multi-Factor Authentication, and Role-Based Access Control, provisioned on a least-privilege, need-to-know basis
  • Phish-resistant MFA through the customer’s own identity provider, including FIDO2/WebAuthn security keys and smartcards via Microsoft Entra ID
  • SCIM provisioning for automated user onboarding and offboarding
  • Zero Trust architecture, with geo-restriction and IP allow/deny lists at the tenant and per-content level
  • Tenant isolation enforced at the application, database, and storage layers
  • All activity logged and monitored for suspicious behavior, with audit trails retained for compliance

VIDIZMO Staff Access

VIDIZMO staff do not hold standing access to customer data. Access is granted only through a break-glass process: time-bound, requiring MFA, and fully logged for review.

FAQ

Access Control & Identity, asked and answered

What authentication methods does VIDIZMO support?

VIDIZMO supports single sign-on (SSO) and multi-factor authentication (MFA), letting your organization enforce its existing identity policies and reduce the risk of compromised credentials.

How are user permissions managed within VIDIZMO?

Access is controlled through role-based permissions, so users only see and interact with the data and features relevant to their job function.

Can VIDIZMO staff access our data?

VIDIZMO operates on a zero standing access model for its own staff, meaning employees do not have persistent access to customer data by default.

Does VIDIZMO integrate with our existing identity provider?

Yes, SSO support allows VIDIZMO to integrate with your organization's identity provider so access follows the same login and provisioning workflows your team already uses.

Why does access control matter for evidence and sensitive media?

Combining SSO, MFA, role-based permissions, and no standing staff access helps ensure that only authorized, verified users can view or handle sensitive video, evidence, or media assets, supporting accountability and data protection requirements.

Need our security documentation?

Tell us what your review requires and we will send the relevant evidence.