Isolation enforced in the database, not just the interface
Your clients ask you the hard questions about your suppliers. Here are the answers for this one — so you can pass them straight through.
Architecture
Multi-tenant with row-level security
Row-level security applies on every table. A partner sees only their own practice and their own clients; a client login is scoped to that single client.
Server-side role checks
Roles live in a dedicated role table and are checked server-side. There is no client-side privilege logic to tamper with.
OWASP Top 10 reviewed
The security posture is reviewed against the OWASP Top 10, with PII exposure controls and tenant-leak guards enforced at the data layer.
Transactional email controls
Branded templates with suppression handling and unsubscribe support, so client communications stay compliant.
Canadian data residency
Canadian data-residency and data-handling documentation available for your own client due diligence packs.
Published legal documentation
Terms of service, privacy policy, acceptable use policy, and a data processing agreement are published and available on request.
Entitlements and access
- Two-level module entitlement: platform operator grants to the partner, partner grants to the client.
- Role-scoped client access — AI Program Manager and Staff each see only their own surfaces.
- Seat management and invite claiming controlled by the partner practice.
- Suspension preserves data; hard delete performs a full, verifiable cleanup.
Integrations
- Microsoft 365 and Outlook for calendar and mail-adjacent workflows.
- Microsoft Teams for the staff-facing AI Q&A bot and tool-request intake.
- Per-partner white-label subdomains, for example security.vcisohub.io.
- Branded PDF and document export across policies, plans, and QBRs.
Need the full due diligence pack?
We will share architecture detail, residency documentation, and the legal set.
