Security, privacy and compliance

Our enterprise-proof platform is built on your principles of data security and data privacy. This ensures that you are fully compliant with the legal requirements set forth.

All personal data is processed within the European Economic Area (EEA).

Vormats guarantees that all your personal data and information does not leave the European Economic Area (EEA). They are processed and stored here, including by affiliated sub-processors.

Security

Singe Sign-On (SSO).

SSO is usable by external enterprise identity providers that comply with the SAML standard. Vormats is optimized for federation with Azure, AuthO, Google and OpenAM.

Data encryption

Data is secured with world-class encryption, both "in transit" with TLS 1.2+ and "at rest" with the AES-256 algorithm, with frequent encrypted backups.

Vulnerability scans

The Vormats platform is monitored for security events with third-party vulnerability scanning software and architecture-specific monitoring tools.

Penetration testing

Our systems undergo regular penetration testing conducted by an independent professional. The results are recorded in the change management register to ensure continuous improvement of Vormats' information security management system.

IT architecture and infrastructure

The IT foundation of our platform and systems is based on the ability to do business with all companies worldwide, regardless of industry and regulation.

Data classification

Vormats' data classification system allows videos to be easily classified by the video owner through three levels of confidentiality. The content of the video determines whether passwords and sanity checks are mandatory.

Application Development

Vormats' development process follows OWASP top-10 standards and the Secure Software Development Lifecycle (SDLC) for building secure applications.

Two-step verification (2FA).

Our authentication system uses industry best practice mechanisms and complies with strict regulations such as HIPPA. Our system is expandable with 2FA via Microsoft and Google authenticators

External independent auditor

Vormats hired NAQ-Cyber as an external independent auditor to periodically review processes and systems for compliance with information security policies and other requirements.

Privacy awareness training

All employees and contractors are regularly trained by our partner NAQ-Cyber and are required to take our cybersecurity and AVG training upon commencement, after which they must re-take the training annually and complete the associated exams

Compliance

AVG

Our platform is designed within the framework of the General Data Protection Regulation (AVG), so you are fully compliant with legal requirements.

ISO 27001

Our ISO/IEC 27001 certification confirms the measures we have taken regarding customer data within the meaning of the General Data Protection Regulation (AVG).

IASME Governance

IASME Governance is an Information Assurance standard designed to help easily and affordably improve cyber security for small and medium-sized enterprises (SMEs).

SOC 2 Type II

Vormats' infrastructure is managed by a trusted cloud service provider subject to the Service Organization Controls (Soc2) (Type II) Trust Services Principles.

FAQ for Security, Privacy and Compliance

We are transparent about the technical and organizational measures we take and are happy to provide open insight into them.

Book a 30-minute Vormats demo.

Get a personalized demo of the Vormats platform.
Learn without obligation how other organizations use video.
Get inspired about video possibilities for your organization.
These organizations led the way: