Security
Last updated: July 21, 2026
MSPs trust vCIO Blueprint with sensitive information about their clients’ technology posture. This page describes the practices we use to protect that data. It is written to be accurate for the product as it exists today, an early-access platform, rather than aspirational.
Infrastructure
- The application runs on managed cloud infrastructure; we do not operate our own physical servers.
- Data is stored in a managed PostgreSQL database with encryption at rest provided by the platform.
- All traffic between your browser and the service is encrypted in transit with TLS.
Tenant isolation and access control
- Every record is scoped to your organization (tenant) and queries are filtered by tenant on the server.
- Role-based access separates MSP administrators, vCIO engineers, and read-only client portal users.
- Client portal users can only see their own organization’s scorecard, roadmap, and reports.
Authentication
- Authentication is handled by a managed identity provider with securely hashed credentials.
- Password reset flows use time-limited, single-use links.
Payments
Subscription payments are processed by a PCI-DSS compliant payment processor. Card numbers never touch our servers.
Certifications
vCIO Blueprint does not yet hold formal certifications such as SOC 2 or ISO 27001. We say so plainly because our product exists to help you communicate honestly about maturity, and we hold ourselves to the same standard. Formal audit readiness is on our roadmap.
Reporting a vulnerability
If you believe you have found a security issue, please email sales@vCIOBlueprint.com with details. We will acknowledge your report and keep you informed as we investigate. Please do not access data that is not yours while researching.