Security and trust
Security designed to earn confidence.
Security at VissoraX is about more than cybersecurity alone. Financial infrastructure asks people and organizations to place real trust in the systems they use.
That trust should be earned through disciplined controls, attributable evidence, clear accountability, and claims that stay within what the evidence can actually support.
Cybersecurity is part of that responsibility. So are compliance discipline, testing, remediation, governance, and knowing who is responsible when a decision or conclusion has to be made.
Compliance-grade discipline
Confidence backed by discipline
Security should not depend on vague promises.
VissoraX approaches security through compliance-grade discipline: requirements connected to controls, evidence that keeps its provenance, testing that can surface gaps, and remediation that stays connected to what was found.
Our controlled compliance source foundation contains 796 unique source-specific obligations across seven source packages:
- NIST CSF 2.0
- SOC 2 Trust Services
- ISO/IEC 27001
- GDPR
- CCPA/CPRA
- GLBA
- AML/KYC
That population is a source foundation for disciplined security and assurance work. It is not a certification, a universal compliance claim, or proof that every control has been implemented, tested, or independently assessed.
Evidence and accountability
What that discipline is meant to create
Clear responsibility
Security decisions, risk acceptance, and external conclusions stay with the people or organizations responsible for making them.
Evidence with provenance
Received evidence stays connected to where it came from, helping preserve what the evidence actually shows instead of rewriting its meaning after the fact.
Testing that leads somewhere
Tests, findings, risks, exceptions, incidents, and remediation remain connected so gaps can be understood and followed through rather than disappearing into a checklist.
Bounded conclusions
Security and assurance conclusions should reflect what the available evidence supports — no more and no less.
Framework context
Framework context without overclaiming
Different frameworks and regimes answer different questions. Their presence in VissoraX's controlled source population does not turn them into certifications or automatically establish legal applicability.
SOC 2 Trust Services
SOC 2 informs readiness and control implementation work. An examination and SOC 2 report require an independent service auditor.
ISO/IEC 27001
ISO/IEC 27001 informs certification readiness and control implementation work. Certification requires an external certification body.
NIST CSF 2.0
NIST CSF 2.0 provides a framework for cybersecurity alignment and implementation. It is not a certification.
GDPR and CCPA/CPRA
These privacy regimes contribute requirements where they apply to the relevant scope. Their inclusion in the controlled source population does not establish universal applicability or compliance.
GLBA and AML/KYC
These regimes likewise contribute requirements where applicable. They are not certifications or external assurance conclusions.
Sentry assurance
Sentry keeps assurance connected
Sentry is VissoraX's infrastructure platform for assurance work.
It helps connect requirements, controls, expected evidence, received evidence, tests, findings, risks, incidents, and remediation so the available evidence can be understood in context over time.
Sentry does not self-certify VissoraX, replace an auditor or certification body, manufacture missing evidence, create legal applicability, or turn incomplete evidence into a finished assurance conclusion.
Its role is to help keep the work connected, attributable, and clear.
Vulnerability reporting
Security is also an ongoing responsibility
Security does not end with a framework, control, or document.
If you believe you have found a security issue affecting VissoraX, we want to know.