Security and trust

Security designed to earn confidence.

Security at VissoraX is about more than cybersecurity alone. Financial infrastructure asks people and organizations to place real trust in the systems they use.

That trust should be earned through disciplined controls, attributable evidence, clear accountability, and claims that stay within what the evidence can actually support.

Cybersecurity is part of that responsibility. So are compliance discipline, testing, remediation, governance, and knowing who is responsible when a decision or conclusion has to be made.

Compliance-grade discipline

Confidence backed by discipline

Security should not depend on vague promises.

VissoraX approaches security through compliance-grade discipline: requirements connected to controls, evidence that keeps its provenance, testing that can surface gaps, and remediation that stays connected to what was found.

796unique source-specific obligations
7source packages

Our controlled compliance source foundation contains 796 unique source-specific obligations across seven source packages:

  • NIST CSF 2.0
  • SOC 2 Trust Services
  • ISO/IEC 27001
  • GDPR
  • CCPA/CPRA
  • GLBA
  • AML/KYC

That population is a source foundation for disciplined security and assurance work. It is not a certification, a universal compliance claim, or proof that every control has been implemented, tested, or independently assessed.

Evidence and accountability

What that discipline is meant to create

Clear responsibility

Security decisions, risk acceptance, and external conclusions stay with the people or organizations responsible for making them.

Evidence with provenance

Received evidence stays connected to where it came from, helping preserve what the evidence actually shows instead of rewriting its meaning after the fact.

Testing that leads somewhere

Tests, findings, risks, exceptions, incidents, and remediation remain connected so gaps can be understood and followed through rather than disappearing into a checklist.

Bounded conclusions

Security and assurance conclusions should reflect what the available evidence supports — no more and no less.

Framework context

Framework context without overclaiming

Different frameworks and regimes answer different questions. Their presence in VissoraX's controlled source population does not turn them into certifications or automatically establish legal applicability.

SOC 2 Trust Services

SOC 2 informs readiness and control implementation work. An examination and SOC 2 report require an independent service auditor.

ISO/IEC 27001

ISO/IEC 27001 informs certification readiness and control implementation work. Certification requires an external certification body.

NIST CSF 2.0

NIST CSF 2.0 provides a framework for cybersecurity alignment and implementation. It is not a certification.

GDPR and CCPA/CPRA

These privacy regimes contribute requirements where they apply to the relevant scope. Their inclusion in the controlled source population does not establish universal applicability or compliance.

GLBA and AML/KYC

These regimes likewise contribute requirements where applicable. They are not certifications or external assurance conclusions.

Sentry assurance

Sentry keeps assurance connected

Sentry is VissoraX's infrastructure platform for assurance work.

It helps connect requirements, controls, expected evidence, received evidence, tests, findings, risks, incidents, and remediation so the available evidence can be understood in context over time.

Sentry does not self-certify VissoraX, replace an auditor or certification body, manufacture missing evidence, create legal applicability, or turn incomplete evidence into a finished assurance conclusion.

Its role is to help keep the work connected, attributable, and clear.

Vulnerability reporting

Security is also an ongoing responsibility

Security does not end with a framework, control, or document.

If you believe you have found a security issue affecting VissoraX, we want to know.

Report a vulnerability