Security

Last updated: September 7, 2026

This page describes how VisionAtlas protects customer data and access in the VisionAtlas application at app.visionatlas.ai. It is intended as an overview of our security practices for the product. The marketing website at visionatlas.ai is covered separately by our Privacy Policy.

See also our Privacy Policy.

1. Scope

This overview applies to the VisionAtlas application hosted at app.visionatlas.ai, including authenticated workspaces, demo environments, and related APIs. Each customer organization operates in an isolated company tenant — users and data from one company are not accessible to another.

2. Infrastructure and encryption

VisionAtlas is built on modern cloud infrastructure designed for reliability and security.

  • Application hosting on Microsoft Azure with HTTPS (TLS) for all traffic in transit
  • Customer data stored in Microsoft Azure SQL Database with encryption enabled for connections and at rest
  • Secrets and credentials managed through environment configuration, not stored in application code

3. Authentication

Users can sign in to app.visionatlas.ai with email and password. Organizations on paid plans can also enable single sign-on with Microsoft Entra ID or Google Workspace. Multi-factor authentication (MFA) is available to strengthen password-based accounts.

  • Password sign-in with optional time-based one-time password (TOTP) MFA
  • SSO via Microsoft Entra ID and Google on all paid plans
  • MFA secrets encrypted at rest using AES-256-GCM
  • One-time backup codes for account recovery
  • Temporary lockout after repeated failed MFA verification attempts
  • Administrators can reset MFA for users when needed

4. Access control

Access within each company tenant is governed by role-based controls. VisionAtlas supports five built-in roles — Admin, Executive, Manager, Department Leader, and Contributor — each with appropriate default permissions for their level of responsibility.

Organizations can enable permission-based authorization (RBAC v2) for granular control over who can view, edit, approve, and manage goals, KPIs, initiatives, users, departments, and settings. Company administrators retain full management access.

5. Visibility and data governance

Beyond role permissions, administrators configure how performance data is shared inside the organization.

  • Transparency profiles — Open, Balanced, or Restricted — as starting presets for visibility defaults
  • Per-entity visibility modes for goals, KPIs, initiatives, observations, risks, and dashboards
  • Object-level visibility so sensitive items can be restricted to owners, participants, or leadership as needed

6. Microsoft 365 activity (optional)

Users may optionally connect Outlook, Teams chat, and Mail so VisionAtlas can suggest a My Week draft from that user’s own meetings and messages. Drafts are assistive only — people edit and submit; VisionAtlas does not auto-post status or write KPI actuals from mail.

  • Activity is encrypted at rest and scoped to the connecting user’s mailbox and chats — not other mailboxes or Teams channels
  • Retention follows company policy (default 90 days)
  • Disconnecting Microsoft removes stored activity for that user

7. Audit and accountability

VisionAtlas maintains an append-only audit log for compliance and operational accountability. Authorized administrators can review and export audit records from the admin console.

  • Events categorized as data, security, or admin activity
  • Login, logout, MFA, permission changes, and impersonation events logged
  • Create, update, delete, and link actions on goals, KPIs, initiatives, users, and other entities recorded with before/after snapshots where applicable
  • Sensitive fields (passwords, tokens, MFA secrets) redacted from audit snapshots

8. AI and third-party services

AI-powered features, such as executive insights, Ask, and briefing drafts, may use Azure OpenAI when configured for your deployment. Customer performance data remains scoped to your company tenant and is not shared across organizations.

We select infrastructure providers with strong security practices. A current list of subprocessors can be provided on request.

9. Security inquiries

If you have questions about how VisionAtlas secures your data, or need to report a security concern, contact us at sales@visionatlas.ai.

This page is provided for informational purposes and does not constitute a contract or legal commitment. Specific security requirements for your organization can be discussed during evaluation and onboarding.