Vizzybl LogoVizzybl LogoVizzybl
Security & Trust

Security at Vizzybl

We monitor how your brand shows up across AI answer engines. Protecting the data you trust us with is foundational to how we build.

  • We never sell your data
  • Never shared to train AI models
  • Encrypted at rest & in transit
  • EU data residency available
  • GDPR-aligned · EU AI Act self-assessed
Your data

Privacy and ownership

Your data is yours. Here is what that means in practice.

We never sell your dataYour brand data, prompts, and results are never sold or rented to anyone — full stop.
We don't share your data to train AI modelsYour prompts are sent to AI providers solely to generate responses — for inference, never to train their models.
Your data is isolated to your tenantEvery customer's data lives in its own tenant, and access is checked on every request — so one customer can never see another's.
We keep only what we needWe store the minimum required to run your monitoring, and internal processing errors are never surfaced as your data.
Infrastructure

Built on hardened cloud infrastructure

Google CloudVizzybl runs on Google Cloud, inheriting its physical, network, and platform security controls.
Encrypted at restAll stored data is encrypted at rest with AES-256 by default.
Encrypted in transitEvery connection is encrypted in transit over HTTPS, with HSTS enforced — no unencrypted traffic.
Connected accounts encryptedCredentials for connected services like Search Console and analytics are individually encrypted with AES-256-GCM using managed keys.
Hardened web securityA strict Content-Security-Policy, anti-clickjacking, and other defense-in-depth headers protect every page.
Abuse protectionRate limiting and bot/abuse detection guard public endpoints against automated attacks.
Access control

Identity and access

Sign in with GoogleAuthentication is handled by Firebase Authentication with Google sign-in — we never store your password.
Multi-factor authenticationAdd an extra layer of protection with authenticator-app MFA (TOTP).
Instant session revocationAccess can be revoked within seconds — sessions don't linger after permissions change.
Least-privilege accessAccess to your workspace is membership-verified on every request, not assumed from a single login.
Scoped automationEach automated agent runs with least-privilege access limited to a single customer's data, and only for the task it is performing.
Compliance

Data residency and compliance

Choose where your data is stored.

Choose your regionChoose where your data is stored — the United States, the European Union, or Asia Pacific.
GDPR-alignedOur practices are aligned with the GDPR, and we've completed an EU AI Act self-assessment.
Audit loggingAdministrative and authentication activity is logged and retained for 7 years; IP addresses are hashed, not stored in the clear.

Security FAQ

Straight answers to the questions we hear most.

  • We never sell your data, and we never share it with AI providers to train their models — your prompts are sent only to generate responses. How we may use data to improve Vizzybl's own service is described in our Privacy Policy.

  • Yes. You choose your storage region at setup — United States, European Union, or Asia Pacific — and that choice determines where your data is held at rest. Processing may also take place in the countries where we and our subprocessors operate, which are listed in our Data Processing Agreement.

  • Every customer has its own tenant, and access is verified on every request. There is no shared view across tenants, so one customer can never reach another's data.

  • Yes — at rest with AES-256 and in transit over HTTPS. Credentials for connected accounts get an additional layer of AES-256-GCM encryption.

  • Sign-in is handled by Firebase Authentication with Google sign-in, and you can enable authenticator-app multi-factor authentication (TOTP) for an extra layer.

  • We send your prompts to AI providers solely to generate responses (inference). On their API tiers, that data is not used to train their models, and connections are encrypted in transit.

  • Our practices are aligned with the GDPR, you can choose EU data storage, and we've completed an EU AI Act self-assessment.

  • Use the “Talk to our team” button below or contact us through the site, and we'll route it to the right people promptly.

Questions about security?

Talk to our team and we'll walk you through exactly how Vizzybl protects your data.

Talk to our team