Security
Built on Trust.
Secure by Design.
Professional services firms trust Vesence with their most sensitive work. We earn that trust through rigorous security practices, independent audits, and a zero-compromise approach to data protection.
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality.
SAML & SSO
Enterprise authentication with single sign-on through your identity provider.
End-to-End Encryption
TLS 1.3 in transit, AES-256 at rest. All data encrypted within a secure Azure private environment.
Zero Data Retention
We never store your information after processing. Your data stays yours.
How We Protect Your Data
Security is not a feature we added. It is the foundation everything at Vesence is built on.
Data Protection
- We never train AI models on your data
- Content Filtering and Abuse Monitoring turned off at the Azure level, so not even Microsoft can access your data
- Documents are processed in memory and never persisted beyond your session
- All customer data is logically isolated per tenant
Infrastructure
- Hosted on Microsoft Azure European Central region with built-in compliance and real-time monitoring
- Zero Trust architecture: every request is verified regardless of origin
- 24/7 automated monitoring and threat detection
- Redundant architecture with automatic failover and point-in-time recovery
Authentication & Access
- Microsoft Entra ID integration with token-based authentication
- Role-Based Access Control (RBAC) with least-privilege principles
- Multi-factor authentication enforced for all accounts
- Comprehensive audit logging and automated session management
Compliance
- GDPR compliant with all processing in the European Union
- SOC 2 Type II certified, aligned with industry standards
- Regular third-party security audits and vulnerability assessments
- Incident response plan with defined SLAs
Zero Trust
Zero Trust, Every Request Verified
Vesence has turned off Content Filtering and Abuse Monitoring from Microsoft Azure. Combined with our Zero Trust architecture, every request is verified and no third party, including our cloud provider, can access your documents or prompts.
EU Data Residency
Processed in Europe
All data processing undertaken by Vesence on behalf of customers takes place exclusively in the European Union, hosted in Azure's European Central region. Full compliance with GDPR and local data sovereignty laws.
We Work
With You
Security is a partnership. Vesence commits to working collaboratively with your firm to address any specific security concerns or compliance requirements. Whether it's a custom security review, a DPA, or aligning with your internal policies, we are here to make it work.
We conduct regular vulnerability assessments and continuously update our processes and systems to adapt to evolving threats and industry standards. Our security posture is never static.
Questions About Security?
We are happy to share our SOC 2 report, discuss our security architecture, or answer any questions your IT and compliance teams may have.
Reach out at support@vesenceai.com