Vision Data Platform
Talk to us
Compliance

Compliance is how we ship — not a quarterly project.

We've worked in regulated industries since 2001. The frameworks below are built into the platform's data layer, not patched on at audit time. New tenants inherit the posture; new features ship against it by default.

SOC 2
Type II

Annual audit. Trust services criteria across security, availability, processing integrity, confidentiality, privacy.

HIPAA
Compliant

BAA available. PHI handling, encryption, access logging, 7-year audit retention on Pro/Enterprise tiers.

FERPA
Compliant

3-year audit retention default. Directory-information controls. Education-records lifecycle managed end-to-end.

PCI-DSS
Compliant

Tokenized card handling. SAQ-A scope for merchants. End-to-end through Stripe, Authorize.Net, and Worldpay integrations.

GDPR
Compliant

Data residency options. Right-to-erasure workflows. Lawful basis tracking per tenant.

CCPA / CPRA
Compliant

Consumer rights workflows: access, deletion, opt-out. Sale/sharing toggle per tenant.

COPPA 2.0
Ready

K-12 youth-data handling. Parental consent flows. Age-gated UX patterns.

CMMC
Roadmap

Level 2 path for federal credentialing partners. Targeting 2026 attestation.

HITRUST
Roadmap

CSF certification on the same path as FedRAMP Moderate.

What this looks like in practice

Per-tenant posture

A K-12 tenant boots with FERPA + COPPA defaults. A clinic boots with HIPAA + state-specific. Same platform, different posture.

Immutable audit log

Every read, write, export, and admin action is logged with cryptographic chaining. Auditors get raw exports; we don't curate.

Evidence on demand

Pen test reports, SOC 2 attestations, BAAs, and DPA templates shared under NDA after second meeting. No marketing fluff.

Need an evidence package for your security team?

Request the package