Key takeaways
- SOC 2 Type II and ISO 27001 controls underpin the platform.
- C2PA provenance makes captured media independently verifiable.
- GDPR and CCPA rights are supported, with regional residency.
- Security documentation is available for buyer review.
The four frameworks that matter here
SOC 2 Type II covers how controls operate over time — access management, change management, monitoring, and incident response — rather than a point-in-time snapshot.
ISO 27001 covers the information security management system as a whole: risk assessment, policy, training, supplier management, and continual improvement.
C2PA is the content provenance standard that binds capture metadata to the media itself, which is what makes an inspection photo independently verifiable.
GDPR and CCPA govern personal data: lawful basis, residency, subject access, and deletion.
What this means in the product
Access is role-scoped and logged, changes are reviewed and tracked, media carries provenance metadata, and personal data can be exported or deleted on request within the statutory window.
Data residency options let EU and Canadian customers keep media in-region.
Buyer documentation
Security review packs, DPAs, subprocessor lists, and architecture summaries are available to prospects and customers under NDA where applicable — contact us and we will route it to your security team directly.
Read the detail
Each framework has a dedicated page explaining scope, controls, and what it means for your workflow.
Keep reading
People also ask
- Can we get a copy of your SOC 2 report?
- Yes, under NDA. Contact us and we will route it to your security reviewer.
- Do you sign DPAs?
- Yes, including standard contractual clauses where required.
- Do you maintain a subprocessor list?
- Yes, and it is provided as part of the security review pack.
Need a hand with something more specific?
help@virtualinspection.ai