HomeSecurity
Trust Center

Security &
trust center.

What enterprise buyers ask before signing: how data is isolated, encrypted, accessed and audited — and what happens if something goes wrong. Last updated: October 2026.

Architecture — isolation by construction

  • Multi-tenant with row-level security — every business row carries its organization id, enforced by Postgres RLS inside the database itself. Application bugs cannot cross tenants.
  • Provisioned access only — no public sign-up; every account is created by the customer's own admin under a unique org code.
  • Offline-first mobile — field actions queue encrypted on-device and sync over TLS; an unreliable network never means lost data.

Data protection

  • TLS in transit on every connection — app, web admin and API.
  • Encrypted at rest — database and object storage sit on encrypted volumes.
  • Least-privilege roles — role and reporting-line scoping is enforced server-side on every request, not just hidden in the UI.
  • Consent-gated capture — GPS tracking, media uploads and data processing write to the database only after the user's recorded consent; withdrawal revokes immediately.
  • Audit trail — logins, security events and key actions are logged per organization.

Compliance posture

  • GDPR / UK GDPR — data export, erasure and consent withdrawal are built into the product; a standard DPA is available to every customer.
  • India DPDP Act 2023 — named Grievance Officer, consent withdrawal and breach-reporting process in place.
  • CCPA/CPRA — we do not sell or share personal information; rights requests honored.
  • Infrastructure certifications — we deploy on providers holding ISO/IEC 27001 and SOC 2 for their infrastructure (see Sub-processors).

Our own certifications: SOC 2 Type II and ISO 27001 audits for the Visaler platform are on the roadmap — we begin the audit cycle with our first enterprise deployments. Ask for current status.

Vulnerability management & incidents

  • Server-side enforcement — access checks, tenant scoping and rate limits live in the API, not the client.
  • Dependency hygiene — dependencies are reviewed before adoption; no advertising or analytics SDKs exist in the product at all.
  • Incident response — suspected breaches go to admin contacts without undue delay, with scope and containment details (see the DPA).

Report a security issue

Found something? Responsible disclosure welcome — email sales@visaler.com with the details. We acknowledge within 48 hours and never take legal action against good-faith research.