4 min read
Security, compliance, and data protection
How we protect your data and which standards we follow.
We take security and data protection seriously and align our practices with widely recognized standards.
Standards and certifications
- We have a SOC 2 Type 1 report covering how we handle customer data.
- We support GDPR and CCPA privacy rights for personal data.
Data protection and agreements
- Customer data is encrypted, and backups are used only for business continuity.
- You can request a data export or deletion in line with our privacy policy.
- For a Data Processing Agreement or other compliance documents, email security@Viktor.com.
If you need specific reports or paperwork for a security review, our team can point you to the right document.
Security and compliance documents: what's available and how to get them
Available to everyone (public, no request needed):
- Security overview - viktor.com/security
- Trust Center (general security controls) - trust.zetalabs.ai
- Privacy Policy - app.viktor.com/privacy
- Terms of Service - app.viktor.com/terms
- Subprocessor list - published in our Privacy Policy (no NDA)
- Data Processing Agreement (DPA) - available to view
Available on the Enterprise plan (under NDA):
- SOC 2 Type I report
- A signed / executable DPA
- Penetration test summary
- Completed security questionnaires (e.g. HECVAT)
Status of certifications:
- SOC 2 Type I: available now
- SOC 2 Type II: in progress
- ISO 27001: in progress
- HIPAA / BAA: in progress
- Data residency options: coming soon
How to request these documents
The NDA-gated documents are part of our Enterprise plan. If you're interested in Enterprise, reach out via viktor.com/contact-sales and let us know what your review needs. We'll set up the NDA and share the relevant documentation. If you're already an Enterprise customer, contact your account owner.