Last updated September 2026.
Our status
Visibility OS is not SOC 2 certified and has not been audited by an independent CPA firm. We are building the controls a SOC 2 Type I audit looks for, so an audit can follow as the business grows. We will not describe ourselves as compliant or certified until an independent report exists, and we will link it here.
Controls in place today
- Tenant isolation: row-level security in the database, so one customer's data cannot be read by another even if the application had a bug.
- Role-based access inside workspaces (owner, admin, member) and separate role-based staff access (super admin, billing, content, support).
- Secrets and provider API keys are kept on the server only and never sent to the browser.
- Encryption in transit (HTTPS) and a managed database with encryption at rest.
- Rate limiting on sign-in and public forms, and plan limits enforced in the database.
- Audit log of staff actions on customer accounts, with time, actor and request details.
- Automated tests and CI checks on every change; database changes are made through versioned migrations.
- Self-service data export and account deletion.
What we do not have yet
- An independent SOC 2 or ISO 27001 report.
- Formal, documented policies reviewed by an auditor (access review, incident response, change management, vendor management).
- Continuous compliance monitoring and a formal penetration test by a third party.
Roadmap
- Write and approve the core policies.
- Collect evidence continuously with a compliance tool.
- Commission an independent penetration test.
- Start a SOC 2 Type I audit, then Type II.
Security questionnaires
Need answers for a vendor review? Send us your questionnaire at security@visibilityos.ai or through the contact form on our website. We will answer it truthfully, including where the answer is "not yet".
Contact and grievances
Send questions, privacy requests or complaints through our contact form or email legal@visibilityos.ai. We acknowledge grievances within 48 hours and aim to resolve them within 30 days.
Grievance Officer: Ruby Rawat, ruby@garagecollective.agency.
Garage Productions Private Limited, C-102, Tower C, ATS Bouquet, Sector 132, Noida, Gautam Buddha Nagar, Uttar Pradesh 201304, India. GSTIN: 09AAGCG1126N1ZG.
We update this page as our position changes. Report a vulnerability to ${LEGAL.securityEmail}.