SOC 2 Type II
Annual third-party audit of our security, availability, confidentiality, and processing integrity controls. Report available under NDA.
End-to-end encryption on every record. Continuous third-party audit. Every major certification a global employment platform needs — and the reports to prove it.
We do not list badges we do not hold. Every certification below is backed by a third-party auditor's report, which we are happy to share under NDA. Request one via contact.
Annual third-party audit of our security, availability, confidentiality, and processing integrity controls. Report available under NDA.
International standard for information security management. Covers risk assessment, access control, cryptography, and operational security.
Cloud-specific extension to 27001. Controls for shared responsibility between Vectis and our cloud provider, and tenant isolation.
Protection of personally identifiable information in public cloud. Applies to every record we process on behalf of a customer.
Full compliance with the General Data Protection Regulation. DPA available on request. Standard contractual clauses in place for transfers.
California Consumer Privacy Act. Right to know, right to delete, right to opt out, and no sale of personal information.
Payment Card Industry Data Security Standard at the highest level. Applies to the card-handling path when customers pay for the platform.
Administrative, physical, and technical safeguards required to process protected health information for customers who need it.
Every pill below is live in production and monitored twenty-four hours a day by our security operations centre.
Report vulnerabilities to security@vectis.app. We acknowledge within one working day, triage within three, and coordinate disclosure. We do not take legal action against researchers who follow these guidelines.
The current list of sub-processors, their purpose, and the data they touch lives on the DPA page. Updates are announced thirty days in advance to account admins.