Published: privacy policy, cookie policy, sub-processor list, DPA template, and our trust badges. Available under NDA via Trust Center request: SOC 2 Type II report, ISO 27001 SoA, CAIQ Lite v4, pen test summaries, HIPAA BAA. Architecture, residency, retention, and disclosure timeline below. For Compliance program support (NIST 800-171 mapping, ITAR/CMMC evidence tooling), see /compliance.
These are Visitly's own attestations and legal artifacts, the inputs to your vendor risk review of us. Separate from Compliance Program Inputs below (which support your compliance program).
Annual audit by independent CPA firm. Full report available under NDA.
Certified information security management system. Statement of Applicability available under NDA.
Self-attestation answered for all 297 controls. Available on request under NDA.
DPA template published. Sub-processor list published with change-notice cadence. Signed DPA executed at contract.
Standard Contractual Clauses + 72-hour breach notification. Privacy program data-handling commitments.
Visitly supports your covered-entity obligations through encryption, access controls, and a BAA executed at contract.
These are documents, references, and tooling Visitly offers to support the compliance programs you own, HIPAA, ITAR, CMMC, OSHA, NISPOM, FERPA. They're not attestations about Visitly; they're visitor-management inputs to your program. Your auditor / C3PAO / OCR submission / counsel reviews your program; we provide the visitor-side records.
Reference document for input to your CMMC Level 2 evidence package. Visitly's mapping; your C3PAO assessor reviews your program. Available under NDA.
Visitor-side controls (citizenship gating, escort workflow, audit trail) and per-tenant evidence export feed your regulated-area program.
PPE attestation, hazard acknowledgment, and drill-mode rolls with one-click evidence export per audit window. Inputs to your OSHA program.
Visitor logs configurable to HIPAA Privacy Rule retention; BAA executed at contract. Your covered entity owns the program; we provide the visitor-management inputs.
Compliance is a program. Visitly is a tool inside that program. Here's where the boundary sits.
Captures visit records (photo, ID, signed acknowledgments, time-stamped)
Provides watchlist screening, citizenship gating, escort workflow, and presence tracking
Stores records in encrypted, region-pinned infrastructure with audit-log retention
Executes our SOC 2, ISO 27001, and pen-test programs and maintains the artifacts
Offers a BAA, DPA, and the evidence exports your compliance team brings to audits
Notifies you of sub-processor changes and security incidents
Define your site policies, restricted areas, and visitor-classification rules
Designate ITAR / CUI / regulated zones and your citizenship-gating policy
Own your HIPAA covered-entity, ITAR, CMMC, OSHA, FERPA, or other compliance program
Maintain administrator account hygiene and your IdP integration
Determine retention windows that meet your records-management obligations
Document your program for your auditor, C3PAO, OCR submission, or counsel
Visitly does not certify, attest, or guarantee your organization's compliance with any framework. We provide the visitor-management tooling, controls, and evidence that support the program your team designs and operates.
TLS 1.3 in transit · AES-256 at rest · keys managed in AWS KMS with per-tenant rotation.
Configurable per-tenant. Default 7 years for audit events; 90 days for visitor PII unless retained for compliance reason.
Continuous point-in-time recovery · daily snapshots · 35-day backup retention · RPO 5 min · RTO 1 hour.
Least-privilege RBAC · MFA required for all engineering access · production access logged + reviewed quarterly.
Annual third-party pen test (NCC Group most recent · 2025). Summary letter available under NDA.
Report a vulnerability to security@visitly.io. Encrypt with our GPG key. We commit to the timeline below for every report.
Or talk to sales. We'll route you to a human who knows multi-location enterprise deployments, not a BDR running a script.
