The short version.
All data in transit and at rest is encrypted. Customer data is segregated by tenant. Access is least-privilege, audited, and requires hardware-backed MFA for engineers. We run on hardened cloud infrastructure with continuous vulnerability scanning. We disclose incidents promptly per contractual SLAs.
What we do — by area.
In transit & at rest.
TLS 1.3 for all network traffic. AES-256 for data at rest. Keys managed via cloud KMS with rotation.
Least privilege, MFA, audited.
Role-based access, hardware-backed MFA for all engineers, just-in-time elevation, full audit log.
Logical & physical separation.
Customer data is logically segregated by tenant. Enterprise tier supports dedicated infrastructure on request.
Continuous scanning + patches.
SAST/DAST in CI, weekly dependency scans, container vulnerability checks, quarterly third-party pen tests.
24/7 SIEM + alerting.
Real-time security event monitoring with on-call rotation. Anomaly detection on auth and admin actions.
Backups + DR.
Daily encrypted backups with point-in-time recovery. Disaster recovery plan tested quarterly.
Compliance & certifications.
- SOC 2 Type II — audit underway, completion target Q4 2026.
- ISO/IEC 27001 — certification path planned for 2027.
- GDPR — compliant; Data Processing Addendum available on request.
Responsible disclosure.
Found a vulnerability? Please report it to security@virtusoperandi.com. We acknowledge within 2 business days and provide a remediation timeline within 10.
Preview state. Compliance certifications are pursued targets, not yet awarded.