# Protecting Your Data, Inside & Out

Customer Success is built on trust. At Vitally, your trust in us starts with your security and privacy.

## SOC 2 Compliance

Certified to responsibily secure, monitor, and process your data.

## GDPR Compliance

Certified to protect and secure data for privacy in the EU.

## Amazon Web Services

Industry-leading cloud storage and security.

To view the operating status of the Vitally platform, click [here](https://vitally.statuspage.io/).

## Trusted by 600+ Leading B2B Customer Success Teams

FAQ

## Security & Compliance

### Product Security

#### Single Sign-On (SSO)

Vitally customers can add organizational-level security to ensure authorized access to the platform.

#### Role-Based Access

Admins can assign permission levels to manage who has access to settings and data in the Vitally platform.

#### Password Storage & Encryption

Users are required to create complex passwords while all credentials are salted, hashed, and encrypted-at-rest (bcrypt).

### Network Security

#### Data Encryption

All data at rest is encrypted with AES-256 while data in-transit is protected over TLS encryption.

#### Data Hosting

Vitally uses AWS data centers for hosting services and data in the United States (us-east-1, us-east-2), and EU (eu-north-1).

#### Penetration Testing

Vitally contracts 3rd party security organizations to perform annual pentesting on our platform.

#### Incident Response

Vitally is committed to providing best-in-class product experiences with our engineering team on-call to respond to any incidents.

### Compliance

#### SOC 2

Vitally has been tested and audited for SOC 2 (Type 2) compliance. For a copy of Vitally’s SOC 2 report, contact [privacy@vitally.io](mailto:privacy@vitally.io).

#### General Data Protection Regulation (GDPR)

Vitally provides resources and tools for customers to maintain GDPR compliance. Learn more [here](https://docs.vitally.io/en/articles/9825718-gdpr-compliance).

#### PCI Obligation

All payments are processed through Stripe, our third-party partner. To learn more about Stripe’s security and PCI compliance measures, visit: [stripe.com/docs/security](https://docs.stripe.com/security)

## Get in Touch

For any questions or to report a possible vulnerability,

please contact [security@vitally.io](mailto:security@vitally.io?subject=Vitally%20Security%20Question)
