Trust & Security
How VOS handles your data
A plain-language summary of the access controls, encryption, retention, and accountability practices behind every account — written for the people evaluating us, not just the people building us.
Encryption in transit
Every connection to VOS — the app itself, live video and audio sessions, and screen-share traffic — runs over TLS (HTTPS) and encrypted WebRTC/WSS. There is no unencrypted path between a technician, a client, and our servers.
Role-based access control
Every user belongs to exactly one organization with one of three roles — owner, admin, or technician. Only owners and admins can invite or remove teammates, change billing, or update organization branding. Technicians can run sessions but cannot touch account-level settings.
Sign-in uses passwordless magic links sent to a verified email address — there's no shared password to leak, phish, or reuse from another breach.
Enterprise single sign-on
Team plan organizations can connect their own identity provider — Microsoft Entra ID, Okta, Google Workspace, or any OpenID Connect-compatible IdP — so technicians sign in with their work accounts. Connections are provisioned by the account owner, protected by DNS domain verification, and can be enforced with a require SSO policy that disables magic links for your domains entirely.
On the roadmap: SAML 2.0 support for identity providers that require it, and SCIM user provisioning so deactivating a technician in your directory automatically removes their VOS access. If either is a requirement for your rollout, tell us — it moves the timeline.
Security program controls
VOS is operated with written internal controls for access reviews, production change management, vendor review, incident response, backup monitoring, and data retention. Access to production systems is limited to authorized maintainers, reviewed when responsibilities change, and removed when it is no longer needed.
Customer-impacting changes are tracked before release, administrative activity is logged for accountability, and security issues are handled through a defined response process with owner review.
Audit logging
Administrative actions — team invitations and removals, role changes, billing and plan changes, branding updates, and session deletions — are recorded with who did it and when. Account owners and admins can review this activity log at any time from Settings, then Activity log.
Data retention, by design
Saved sessions, recordings, and screenshots are kept for 90 days on the Solo plan and 90 days on the Team plan, then pruned automatically. Retention isn't a manual chore someone forgets to do — it runs on a schedule, tied to your plan, with no configuration required.
Data isolation
Every session, recording, screenshot, and team record is scoped to a single organization ID at the database layer. One company's data is never queryable from another company's session — there is no shared tenant view.
Infrastructure
Video sessions are powered by LiveKit's WebRTC infrastructure. Recordings and screenshots are stored in access-controlled storage; when configured to use S3-compatible object storage (e.g. Cloudflare R2), files are encrypted at rest by the storage provider. Application data lives in a managed MySQL database that is not exposed to the public internet.
Your data, your control
You can export session and billing data on request, and you can delete a session — along with its recording, screenshots, and notes — permanently, at any time, from the Launchpad.
Questions for a security review?
If your procurement or security team needs more detail — a completed questionnaire, a call with engineering, or specifics about the SSO rollout and the SAML/SCIM roadmap — reach out and we'll get you what you need.
