Visure operates its SaaS offering on Microsoft Azure under an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022. This document summarizes the technical and operational controls that protect customer data and the availability of the service.
System / Data Center Overview
Application access
The application is accessed over HTTPS through customer-specific URLs. Each customer environment is provisioned on dedicated, isolated infrastructure, so customer data and runtime environments are separated rather than shared on multi-tenant application instances.
Hosting provider and locations
Infrastructure is hosted on Microsoft Azure. Customer environments are deployed to Azure regions selected to meet the customer's data-residency requirements (for example, regions within the United States or the European Union). Microsoft Azure data centers maintain a broad set of independent certifications, including ISO/IEC 27001, SOC 1/2/3, PCI DSS, and alignment with GDPR. Current attestations are published in the Microsoft Trust Center.
Governance, Policies, and Compliance
ISMS and ISO 27001
Visure is implementing an ISMS aligned to ISO/IEC 27001:2022, covering risk management, secure development, access control, cryptography, logging and monitoring, change management, vulnerability management, and incident response. (ISO 27001 certification is in progress; we are happy to share current status on request.)
Policies maintained
- Information Security Policy — governs secure management of infrastructure, applications, and data, including access control, encryption, vulnerability management, and incident response.
- Privacy Policy — describes how personal and sensitive data is collected, processed, stored, and deleted.
- Secure Development Policy — defines the secure development lifecycle requirements applied to all production code.
Detailed policy documentation is available to customers under NDA on request.
Provider compliance
As our cloud provider, Microsoft Azure maintains SOC 1/2/3, ISO/IEC 27001, PCI DSS, HIPAA, and GDPR-aligned compliance programs. Provider compliance reports are available through the Microsoft Trust Center.
Secure Development
We follow secure-development-lifecycle (SDLC) practices:
- Change management — all changes reach production through version control and pull requests requiring human review; direct, unreviewed changes to production are not permitted.
- Code review and static analysis — code is peer-reviewed, and automated static analysis runs in our CI pipeline before merge.
- Dependency and supply-chain scanning — third-party dependencies are pinned and continuously scanned for known vulnerabilities, with findings remediated under our vulnerability-management SLAs.
- Infrastructure as code — infrastructure changes are made through reviewed, version-controlled definitions with secure-by-default configuration, not ad-hoc portal changes.
- Environment separation — development, staging, and production are separated, and production or real customer data is not used in development or test environments.
Data Security
Encryption at rest
All data is encrypted at rest using AES-256.
Encryption in transit
All data in transit is encrypted using TLS 1.2 or higher (TLS 1.3 where supported by the client). Certificate validation is enforced; insecure protocols and ciphers are disabled.
Secrets management
Application and infrastructure secrets are held in a managed secret store. Service-to-service authentication uses platform-managed identities wherever possible, minimizing the use of stored credentials.
Backup, retention, and deletion
- Customer data is backed up daily, with backups retained for 30 days in access-controlled storage.
- Backup storage is private by default; public/anonymous access is disabled.
- On contract termination or upon request, data is deleted following a secure deletion process consistent with Azure's media-sanitization practices, so no residual customer data remains.
Access Control and Identity
- Centralized identity — access is managed through Microsoft Entra ID (Azure AD).
- Single Sign-On (SSO) — SSO via Entra ID / SAML is supported for customer integration.
- Role-Based Access Control (RBAC) — access is governed by RBAC, with permissions granted to roles/groups rather than individuals.
- Least privilege — users and services receive the minimum access required for their function.
- Privileged access — administrative access to production is restricted and granted just-in-time with approval, rather than as standing privileged access.
- Multi-Factor Authentication (MFA) — MFA is enforced for administrative and operational access to production environments.
Network Security
- Management ports are not exposed to the public internet.
- Network access is restricted on a least-access basis.
- Storage and other data services are private by default; public network access requires documented justification.
- Network flow logs and diagnostics are enabled and centrally collected.
Logging and Monitoring
- Security monitoring — a centralized monitoring capability provides real-time log analysis, alerting, and vulnerability detection across the environment.
- Cloud security posture — cloud-native tooling provides infrastructure health, security-posture assessment, and alerting.
- Centralized logging — security-relevant events (authentication, authorization, privileged operations, configuration changes) are logged centrally for traceability and retained per policy.
Vulnerability and Patch Management
- Vulnerabilities are identified continuously through security monitoring, cloud-native posture assessment, and dependency scanning.
- Remediation is prioritized by severity under defined ISMS SLAs, with critical vulnerabilities expedited and routine updates applied on a regular cadence.
- Patching and remediation follow the same change-management process as any other change, so production changes are reviewed and traceable.
Incident Response
Visure maintains an incident-response process covering detection, triage, containment, remediation, and post-incident review. Security alerts from the monitoring stack feed this process, and customers are notified of incidents affecting their data in line with contractual and regulatory obligations.
Major Subprocessors
Subprocessor Purpose Microsoft Azure Cloud hosting, infrastructure, DNS, and platform services Zendesk Support ticketing and incident communication
A current, authoritative subprocessor list is maintained separately and provided on request.
A current, authoritative subprocessor list is maintained separately and provided on request.
Summary
- Compliance — ISO/IEC 27001 ISMS (implementation in progress); hosted on Azure (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR-aligned).
- Data security — AES-256 at rest, TLS 1.2+ in transit, managed-secret-store credentials, daily backups with 30-day retention, secure deletion.
- Access control — Entra ID SSO, RBAC, least privilege, just-in-time privileged access, MFA on production.
- Tenant isolation — dedicated per-customer environments.
- Monitoring — centralized security monitoring, cloud-native posture assessment, and centralized logging.
- Change management — all changes via reviewed pull requests and infrastructure as code.
If you experience any issues configuring this, please reach out to our support team by emailing support@visuresolutions.com.
Comments
0 comments
Please sign in to leave a comment.