Skip to main content
Has your work email already leaked?Run the 10-second check
Trust and compliance

Independently audited. Not self-attested.

A security provider asking you to trust it is asking a lot. This page is the evidence: who audited us, what they examined, what we can send you, and, just as importantly, which of our claims are audits and which are not.

SOC 2 Type II, AICPA SOC for Service OrganizationsAICPA SOC and ISO 27001 certified, audited by A-LIGN
The short version

Vijilan Security is SOC 2 Type II certified and ISO/IEC 27001 certified. Both were audited by A-LIGN, an independent assessment firm.

Vijilan is also a CrowdStrike Powered Service Provider. That is a designation inside CrowdStrike's partner program and it is not an audit, which is why it is listed separately here.

For HIPAA, PCI DSS and CMMC Level 2 we provide evidence packs: the control evidence our service generates, mapped to those frameworks, produced on request. No managed security provider is "HIPAA certified", because there is no such certification.

Individual credentials such as CISSP belong to the people who hold them, not to the company.

Read this part first

Four kinds of claim, and they are not interchangeable.

Security marketing collapses these into one word, and a buyer comparing providers ends up comparing sentences rather than substance. Ours are separated on purpose.

1. Certifications

An independent auditor examined us and issued a report. SOC 2 Type II and ISO/IEC 27001, both through A-LIGN. This is the strongest category because somebody outside the company is accountable for the answer.

2. Partner designations

Earned inside a vendor’s partner program: CrowdStrike Powered Service Provider. It means a vendor authorized us to deliver managed services on their platform. It is a real thing and it is not an audit.

3. Evidence packs

HIPAA, PCI DSS and CMMC Level 2. Control evidence our service generates, mapped to the framework and produced on request. These support your assessment; they are not a certification of ours, and any provider claiming otherwise is describing something that does not exist.

4. Staff credentials

Held by named people, and they leave when those people do. Listing them as company credentials is a common and slightly dishonest shortcut. Ours are below, attached to the roles that hold them.

Audited

What we hold.

SOC 2 Type II

Audited by A-LIGN

A Type II report examines whether controls were designed correctly and operated effectively across a period, rather than at a single moment. That distinction is the whole value: it is evidence of behavior over time, not a snapshot.

ISO/IEC 27001

Audited by A-LIGN

The international standard for an information security management system. It certifies the system that manages risk, including how risks are identified, treated and reviewed, rather than certifying any single control.

The five Trust Services Criteria a SOC 2 examines

Security
Protection against unauthorized access, physical and logical.
Availability
Systems are available for operation and use as committed.
Processing integrity
Processing is complete, valid, accurate, timely and authorized.
Confidentiality
Information designated confidential is protected as committed.
Privacy
Personal information is collected, used, retained and disposed of as committed.

A report may cover Security alone or Security plus others; the scope is stated in the report itself, which is the document to read rather than the badge.

People, not the company

Who holds what.

Founder and CEO

KayVon Nejad holds the CISSP, alongside executive study at Wharton in security data analytics, MIT in information systems and Carnegie Mellon in incident response.

More about KayVon

The SOC

Analysts and engineers on the platform certifications the work actually requires: CrowdStrike CCFA, CCFR, CCFH, CCSE and CCIS, plus CISSP and Cribl certification. The SOC operates in English, Spanish and Portuguese.

How the SOC is staffed
Questions

The ones assessments actually ask.

Is Vijilan SOC 2 certified?

Yes. Vijilan holds a SOC 2 Type II report, audited by A-LIGN. Type II is the version that examines whether controls operated effectively over a period rather than existed on a given day, which is the one a reviewer should ask for.

Is Vijilan ISO 27001 certified?

Yes, ISO/IEC 27001, also through A-LIGN. It is worth saying plainly because the phrase "ISO 27001 ready" circulates widely and means something different: ready describes an intention to be audited, certified means an auditor has been.

Can we have a copy of the SOC 2 report?

Yes, under NDA. Reports of this kind are not published openly because they describe control environments in detail. Ask through the contact form or your account contact and we will route it.

Are you HIPAA, PCI or CMMC certified?

No, and no provider honestly is, because those three do not work that way. HIPAA has no certifying body. PCI DSS certifies an assessed environment for a defined scope rather than a company. CMMC certifies a specific organization against a specific contract requirement. What we provide is evidence packs: the control evidence our service generates, mapped to those frameworks, produced on request so your own assessment has something to work from.

What is a CrowdStrike Powered Service Provider?

It is a designation inside CrowdStrike’s partner program, confirming Vijilan is authorized to deliver managed services on the Falcon platform. It is worth keeping separate from the certifications above, because it is not an audit and nobody should read it as one.

Who audits Vijilan?

A-LIGN, an independent cybersecurity and compliance assessment firm, for both the SOC 2 Type II and the ISO/IEC 27001 certification.

Where is customer data processed, and by whom?

Every third party that may process data on our behalf is listed publicly on the subprocessors page, along with what each one does. The data processing addendum and the service level agreement are also published rather than sent on request.

We are running a vendor security assessment. What do you need from us?

Usually nothing more than the questionnaire. If it is a standard format we will complete it directly; if you would rather start from our documentation, the SOC 2 report under NDA plus the published DPA, SLA and list of subprocessors answer most of what these assessments ask.

We're online · book a SOC walkthrough today

Still have a question
your questionnaire needs answered?

Send it over. If it is a standard format we will complete it directly, and if it is not, we will answer it as written rather than sending a brochure back.