TRUST CENTER

The evidence your InfoSec, legal, and procurement teams typically request about us as a vendor.

Published: privacy policy, cookie policy, sub-processor list, DPA template, and our trust badges. Available under NDA via Trust Center request: SOC 2 Type II report, ISO 27001 SoA, CAIQ Lite v4, pen test summaries, HIPAA BAA. Architecture, residency, retention, and disclosure timeline below. For Compliance program support (NIST 800-171 mapping, ITAR/CMMC evidence tooling), see /compliance.

99.97% uptime · 90 days
Sub-processor list published
DPA template published
NDA-gated reports on request
VISITLY'S ATTESTATIONS

What InfoSec and procurement review about us as a vendor.

These are Visitly's own attestations and legal artifacts, the inputs to your vendor risk review of us. Separate from Compliance Program Inputs below (which support your compliance program).

SOC 2 Type II

Annual audit by independent CPA firm. Full report available under NDA.

ISO 27001

Certified information security management system. Statement of Applicability available under NDA.

CSA STAR CAIQ Lite v4

Self-attestation answered for all 297 controls. Available on request under NDA.

DPA + Sub-processors

DPA template published. Sub-processor list published with change-notice cadence. Signed DPA executed at contract.

Download DPA template

GDPR + CCPA

Standard Contractual Clauses + 72-hour breach notification. Privacy program data-handling commitments.

Read GDPR policy

HIPAA BAA available

Visitly supports your covered-entity obligations through encryption, access controls, and a BAA executed at contract.

Request BAA execution
COMPLIANCE PROGRAM INPUTS

What we provide as inputs to your compliance program.

These are documents, references, and tooling Visitly offers to support the compliance programs you own, HIPAA, ITAR, CMMC, OSHA, NISPOM, FERPA. They're not attestations about Visitly; they're visitor-management inputs to your program. Your auditor / C3PAO / OCR submission / counsel reviews your program; we provide the visitor-side records.

NIST 800-171 Rev 2 control-mapping reference

Reference document for input to your CMMC Level 2 evidence package. Visitly's mapping; your C3PAO assessor reviews your program. Available under NDA.

ITAR / CMMC / NISPOM evidence tooling

Visitor-side controls (citizenship gating, escort workflow, audit trail) and per-tenant evidence export feed your regulated-area program.

Read Manufacturing playbook

OSHA evidence tooling

PPE attestation, hazard acknowledgment, and drill-mode rolls with one-click evidence export per audit window. Inputs to your OSHA program.

Read Workplace Safety

HIPAA program support

Visitor logs configurable to HIPAA Privacy Rule retention; BAA executed at contract. Your covered entity owns the program; we provide the visitor-management inputs.

Read Healthcare playbook
SHARED RESPONSIBILITY

What Visitly does. What you do.

Compliance is a program. Visitly is a tool inside that program. Here's where the boundary sits.

What Visitly does
  • Captures visit records (photo, ID, signed acknowledgments, time-stamped)

  • Provides watchlist screening, citizenship gating, escort workflow, and presence tracking

  • Stores records in encrypted, region-pinned infrastructure with audit-log retention

  • Executes our SOC 2, ISO 27001, and pen-test programs and maintains the artifacts

  • Offers a BAA, DPA, and the evidence exports your compliance team brings to audits

  • Notifies you of sub-processor changes and security incidents

What you do
  • Define your site policies, restricted areas, and visitor-classification rules

  • Designate ITAR / CUI / regulated zones and your citizenship-gating policy

  • Own your HIPAA covered-entity, ITAR, CMMC, OSHA, FERPA, or other compliance program

  • Maintain administrator account hygiene and your IdP integration

  • Determine retention windows that meet your records-management obligations

  • Document your program for your auditor, C3PAO, OCR submission, or counsel

Visitly does not certify, attest, or guarantee your organization's compliance with any framework. We provide the visitor-management tooling, controls, and evidence that support the program your team designs and operates.

DATA PRACTICES

Encryption, residency, retention, and access, defaults that don't need an exception.

Encryption

TLS 1.3 in transit · AES-256 at rest · keys managed in AWS KMS with per-tenant rotation.

Retention

Configurable per-tenant. Default 7 years for audit events; 90 days for visitor PII unless retained for compliance reason.

Backup + recovery

Continuous point-in-time recovery · daily snapshots · 35-day backup retention · RPO 5 min · RTO 1 hour.

Access control (internal)

Least-privilege RBAC · MFA required for all engineering access · production access logged + reviewed quarterly.

Penetration testing

Annual third-party pen test (NCC Group most recent · 2025). Summary letter available under NDA.

RESPONSIBLE DISCLOSURE

Security disclosure

Report a vulnerability to security@visitly.io. Encrypt with our GPG key. We commit to the timeline below for every report.

GPG fingerprint

8B91 2E9F 4A37 5D2C 6F18 B4E7 1A23 9D88 5C04 EE2A
1

Report received

Within 1 business day
2

Triage complete

Within 3 business days
3

Severity-graded plan + ETA

Within 5 business days
4

Patch deployed (critical/high)

Within 14 calendar days
5

Public disclosure (if applicable)

Coordinated with reporter
TALK TO US

Skip the demo gauntlet. Pull our Trust Center and pricing yourself.

Or talk to sales. We'll route you to a human who knows multi-location enterprise deployments, not a BDR running a script.

CTA banner image