Security and Subprocessors

Last updated July 24, 2026

What we run, who else touches the data, and what we do not claim. Written so a reviewer can check it rather than take our word for it.

Where customer data lives

Customer data — CAD models, captured images, and inspection records — is hosted on Microsoft Azure in the West US 2 region, using Azure Database for PostgreSQL Flexible Server and Azure Blob Storage. Both encrypt data at rest with platform-managed keys by default. Traffic to our services is served over HTTPS.

A database and its object-storage container are provisioned and treated as a matched pair, so inspection records and the evidence frames they reference cannot drift onto separate customers' storage.

On-premise and edge deployments

Some deployments run on hardware inside a customer's facility, at the line. In that configuration inspection data is produced and held on that hardware, and what — if anything — is forwarded to a cloud environment is set by the deployment agreement.

Disk encryption, secure boot, and physical anti-tamper measures on customer-sited appliances are configured per deployment and are not enabled by default. If those controls matter for your site, raise it during scoping and we will specify them explicitly rather than leave it implied.

Subprocessors

These providers process customer data on our instructions. We will update this page before adding a subprocessor that handles customer data.

ProviderPurposeRegion
Microsoft AzureHosting, database, and object storage for customer data (PostgreSQL Flexible Server and Blob Storage)United States (West US 2)
GoogleCompany email, and delivery of transactional email such as verification and password-reset messagesUnited States
PostHogProduct analytics on the public website only, loaded solely with visitor consentUnited States

We also use Hetzner for development and staging environments. Hetzner does not hold customer production data, which is why it is not listed as a subprocessor above.

Access and authentication

  • Passwords are stored only as salted hashes. We cannot read or recover them.
  • Sessions are cookie-based and expire; you can end your own sessions from within the application.
  • Sign-in, sign-up, and password-reset endpoints are rate-limited to blunt credential guessing.
  • Data access is scoped to your organization, and that scope is derived from the server-side session rather than from anything the browser sends.
  • Mutating requests authenticated by cookie are checked against an allowlist of known origins.

What we do not claim

We would rather be checkable than impressive, so to be explicit:

  • We do not currently hold SOC 2 or ISO 27001 certification, and we do not describe our process as certified or audited.
  • We do not claim customer-managed encryption keys; at-rest encryption uses the platform-managed keys the cloud provider supplies.
  • We do not claim full-disk encryption or secure boot on customer-sited appliances by default — see the on-premise section above.
  • We do not claim a contractual uptime guarantee outside of a signed agreement.

If your procurement process needs a control we do not yet have, tell us what it is and we will give you a straight answer about whether and when we can meet it.

Reporting a vulnerability

Email contact@visceral.vision with enough detail to reproduce the issue. We will acknowledge it, keep you updated while we fix it, and credit you if you would like. We will not pursue legal action against researchers acting in good faith who avoid privacy violations, data destruction, and service disruption.

Related

See our Privacy Policy for what we collect and Terms of Service for the contractual side. GOAD LLC is a Delaware limited liability company.