Security
Last updated: June 18, 2026
This page describes how VisionAtlas protects customer data and access in the VisionAtlas application at app.visionatlas.ai. It is intended as an overview of our security practices for the product. The marketing website at visionatlas.ai is covered separately by our Privacy Policy.
See also our Privacy Policy.
1. Scope
This overview applies to the VisionAtlas application hosted at app.visionatlas.ai, including authenticated workspaces, demo environments, and related APIs. Each customer organization operates in an isolated company tenant — users and data from one company are not accessible to another.
2. Infrastructure and encryption
VisionAtlas is built on modern cloud infrastructure designed for reliability and security.
- Application hosting on Microsoft Azure with HTTPS (TLS) for all traffic in transit
- Customer data stored in Microsoft Azure SQL Database with encryption enabled for connections and at rest
- Secrets and credentials managed through environment configuration, not stored in application code
3. Authentication
Users sign in to app.visionatlas.ai with email and password. Organizations can strengthen account security with optional multi-factor authentication (MFA).
- Time-based one-time password (TOTP) MFA, enrollable from user settings
- MFA secrets encrypted at rest using AES-256-GCM
- One-time backup codes for account recovery
- Temporary lockout after repeated failed MFA verification attempts
- Administrators can reset MFA for users when needed
4. Access control
Access within each company tenant is governed by role-based controls. VisionAtlas supports five built-in roles — Admin, Executive, Manager, Department Leader, and Contributor — each with appropriate default permissions for their level of responsibility.
Organizations can enable permission-based authorization (RBAC v2) for granular control over who can view, edit, approve, and manage goals, KPIs, initiatives, users, departments, and settings. Company administrators retain full management access.
5. Visibility and data governance
Beyond role permissions, administrators configure how performance data is shared inside the organization.
- Transparency profiles — Open, Balanced, or Restricted — as starting presets for visibility defaults
- Per-entity visibility modes for goals, KPIs, initiatives, observations, risks, and dashboards
- Object-level visibility so sensitive items can be restricted to owners, participants, or leadership as needed
6. Audit and accountability
VisionAtlas maintains an append-only audit log for compliance and operational accountability. Authorized administrators can review and export audit records from the admin console.
- Events categorized as data, security, or admin activity
- Login, logout, MFA, permission changes, and impersonation events logged
- Create, update, delete, and link actions on goals, KPIs, initiatives, users, and other entities recorded with before/after snapshots where applicable
- Sensitive fields (passwords, tokens, MFA secrets) redacted from audit snapshots
7. AI and third-party services
AI-powered features, such as executive insights and template suggestions, may use Azure OpenAI when configured for your deployment. Customer performance data remains scoped to your company tenant and is not shared across organizations.
We select infrastructure providers with strong security practices. A current list of subprocessors can be provided on request.
8. Enterprise capabilities
Enterprise plans include additional security and reliability options for organizations with advanced requirements. These capabilities are configured during onboarding and may include:
- Single sign-on (SSO) via SAML
- SCIM user provisioning
- 99.9% uptime service level agreement (SLA)
9. Security inquiries
If you have questions about how VisionAtlas secures your data, or need to report a security concern, contact us at sales@visionatlas.ai.
This page is provided for informational purposes and does not constitute a contract or legal commitment. Specific security requirements for your organization can be discussed during evaluation and onboarding.