We hold your data the way we ask you to hold your customers'
Viglyn stores the evidence that proves your security program works, which makes us part of your supply chain. This page is what we can tell you about how that data is held, and how to ask for the rest.

Six things that are true of every workspace
Not aspirations. These are properties of the product, the same ones it checks your systems for.
Isolation
Tenant isolation is enforced at the database level, so one customer's evidence is never reachable from another's session.
Least privilege
Six built-in roles with object-level permissions. People see the part of the program their role covers, and nothing else.
Scoped outside access
Auditors and vendors get their own access paths at a depth you control, rather than a seat in your workspace.
Integrity at capture
Automated evidence is the actual system response, hashed when it is collected, so tampering after the fact is detectable.
Encryption
Evidence is encrypted, and manual uploads carry a full audit trail from the moment they arrive.
Honest reporting
Gaps are shown as gaps. Out-of-scope items stay visible to auditors, and every scope decision records a reason.

The opinion stays the auditor's
Viglyn is where the audit runs, not who signs it. Auditors work through their own scoped access at a depth you control, and the product is built so a gap can't be quietly presented as anything else.
What we hold, and for how long
Evidence is the response your systems gave, plus the documents you upload. Retention is set per record and shown on the record itself.
- Every evidence record carries its own retention period
- Documents are dated from verifiable metadata, with your confirmation when uncertain
- Evidence exports as verifiable packages you can check outside Viglyn
- What we collect through the website is set out in the privacy policy

Ask us for the paperwork
Security reviews need documents, not web pages. Tell us what your review asks for and we'll send what applies, under NDA where that's appropriate.
- Security overview and architecture summary
- Access control and role model
- Evidence handling, retention, and integrity design
- Data processing terms and sub-processor position
- Incident response and business continuity summary
Security questions can also go straight to infosec@viglyn.com.
Reviewing us as a vendor?
We answer vendor questionnaires the way we'd want ours answered: quickly, in writing, and without dodging the question. Send it over.