Security and trust

Isolation enforced in the database, not just the interface

Your clients ask you the hard questions about your suppliers. Here are the answers for this one — so you can pass them straight through.

Architecture

Multi-tenant with row-level security

Row-level security applies on every table. A partner sees only their own practice and their own clients; a client login is scoped to that single client.

Server-side role checks

Roles live in a dedicated role table and are checked server-side. There is no client-side privilege logic to tamper with.

OWASP Top 10 reviewed

The security posture is reviewed against the OWASP Top 10, with PII exposure controls and tenant-leak guards enforced at the data layer.

Transactional email controls

Branded templates with suppression handling and unsubscribe support, so client communications stay compliant.

Canadian data residency

Canadian data-residency and data-handling documentation available for your own client due diligence packs.

Published legal documentation

Terms of service, privacy policy, acceptable use policy, and a data processing agreement are published and available on request.

Entitlements and access

  • Two-level module entitlement: platform operator grants to the partner, partner grants to the client.
  • Role-scoped client access — AI Program Manager and Staff each see only their own surfaces.
  • Seat management and invite claiming controlled by the partner practice.
  • Suspension preserves data; hard delete performs a full, verifiable cleanup.

Integrations

  • Microsoft 365 and Outlook for calendar and mail-adjacent workflows.
  • Microsoft Teams for the staff-facing AI Q&A bot and tool-request intake.
  • Per-partner white-label subdomains, for example security.vcisohub.io.
  • Branded PDF and document export across policies, plans, and QBRs.

Need the full due diligence pack?

We will share architecture detail, residency documentation, and the legal set.

Request it