EU Hosted
GDPR Aligned
99.5% Uptime Target
Security, Compliance & Reliability at 4Viso
We protect supply chain risk intelligence with strong encryption, EU data residency, and enterprise-grade controls. Explore our practices, policies, and downloadable documentation.
1) Security Overview
Core controls across infrastructure, encryption, access, monitoring, and SDLC.
Infrastructure
EU cloud regions, hardened networks, WAF, least-privilege service architecture.
Encryption
TLS 1.3 in transit; AES‑256 at rest; secrets management and key rotation policies.
Access & Auth
SSO, MFA, RBAC; session timeouts; admin approval flows; audit trails on critical actions.
Monitoring
Centralized logs, SIEM, anomaly detection, alerting, and incident response.
Secure SDLC
Code reviews, dependency scanning, SAST/DAST, CI policy gates, change management.
Testing
Regular third‑party penetration tests; remediation SLAs tracked to closure.
Incident Response (IR) Overview
- Defined IR runbooks and roles; quarterly tabletop exercises.
- Breach notification commitment: within 48 hours, where feasible.
- Post‑incident reviews with action items and owner accountability.
Backup & DR Snapshot
- Automated daily backups; point‑in‑time recovery targets.
- Regular restore tests; RPO/RTO objectives defined.
- Multi‑AZ redundancy for critical services.
2) Compliance & Certifications
4Viso aligns with leading frameworks to safeguard your data.
| Framework | Status | Notes |
|---|---|---|
| GDPR | Compliant | EU entity with DPA & SCCs support. |
| CPRA/CCPA | Compliant | Consumer rights honored, opt‑out cookie controls. |
| ISO 27001 | Aligned | ISMS mapped; certification roadmap. |
| SOC 2 Type II | In Progress | Independent audit underway. |
3) Privacy & Data Handling
Data Residency
Primary hosting within the EU. International transfers protected via Standard Contractual Clauses.
Data Ownership
Customer owns all data. 4Viso acts as a GDPR Data Processor.
Permissions & Visibility
Granular controls for public vs. permission‑based organization data.
Retention & Deletion
Deletion or return at contract end; retention limits applied per policy.
See: Privacy Policy · Cookie Policy · DPA
4) Platform Reliability & Status
Resilient infrastructure with proactive monitoring and failover.
Availability Target
99.5% monthly uptime (excl. scheduled maintenance & force majeure).
Observability
Health checks, SLIs, and alerting on critical paths, plus real‑time dashboards.
Business Continuity
Documented BCDR program; regular exercises and improvement cycles.
5) Legal Documentation
6) Responsible Disclosure
We welcome good‑faith security research and responsible vulnerability reporting.
Policy Summary
- No legal action for good‑faith testing and reporting within scope.
- Do not exfiltrate data or disrupt services.
- Give us reasonable time to remediate before public disclosure.
Report issues via email: info@4viso.com (subject: "Security Report").
8) Contact the Security Team
Questions, compliance docs, or security requests? We’re here to help.
Address
Science Park Antwerp, Galileilaan 15, 2845 Niel, Belgium
