Viktor Security: SOC 2, GDPR, CCPA

The security behind yourAI employee.

Built so your credentials never touch the AI, every sensitive action waits for approval, and your data never trains a model.

SOC 2 compliant

CCPA compliant

GDPR aligned

ChatGPT

ChatGPT in Slack: Search, write, summarize and get work done.

Claude

Anthropic's AI agent for any task — think, write, and code with Claude.

Viktor

Salesforce Partner

Approved by Slack. Listed in the App Directory.

Viktor is published in the official Slack App Directory. That means our OAuth scopes, security posture, and store listing have been reviewed and approved by Slack before we were allowed to ship to customers through their store.

Compliance

Independently audited. Continuously verified.

The audit reports are real, the controls are continuously monitored, and the next audit is always on the calendar.

Standard Status Coverage Documentation
SOC 2 Type 1 Certified Independent attestation that our security controls operate as designed. Type II in progress. Report available under NDA.
GDPR Aligned EU data protection requirements met. DPA available on request.
CCPA Compliant California Consumer Privacy Act requirements met. Privacy documentation available.
Slack App Directory Listed OAuth scopes and security posture vetted before shipment through the Slack store. Public App Directory listing.
ISO 27001 In progress ISMS controls implementation and evidence collection in progress. Controls overview available today; audit evidence shared after certification.

Data handling

What Viktor does. What Viktor does not.

Here's exactly what Viktor touches — and what he never does.

Does

Encrypts everything

TLS 1.2+ in transit. AES-256 at rest. Secrets in dedicated vaults.

Authenticates with SSO

SAML SSO across Okta (inside Slack), Entra ID, Google Workspace, OneLogin and any SAML 2.0 IdP.

Data residency options

US-hosted by default. EU data residency available on Enterprise contracts.

Revokes instantly

Admins can disconnect any integration, pause any user, or kill a running task in one click.

Does not

Train on your data

Your conversations and files never enter a training set — not ours, not our model providers'.

Read your secrets

API keys and tokens are injected at execution time by the tool gateway; the model never sees them.

Act without approval

Money moves, code pushes, and customer emails wait for your explicit approval in Slack.

Share across workspaces

Skills, integrations, and memory are walled off per workspace. No cross-tenant access.

AI Safety

AI brings new risks, and we know how to handle them

Credentials

Your credentials are invisible to the AI

Approvals

You approve every sensitive action

No training

Your data never trains a model

Isolation

Your workspace is fully isolated

A backend tool gateway injects your API keys and OAuth tokens at execution time. The AI model itself never sees them.

Not a policy. The architecture.

Viktor vs AI tools

Independently audited. AI brings new risks, and we know how to handle them

AI employees introduce attack surfaces traditional SaaS does not have. Three controls keep the surface small.

Prompt-injection defense

Untrusted content is rendered as data, not commands. Admins put high-risk tools behind human approval, so an injection can't trigger gated actions like moving money or pushing code on its own.

Named model providers, no-training contracts

Inference runs on OpenAI, Anthropic, and Google. Each is on the public sub-processor list with a no-training agreement for Viktor traffic.

Skills, the persistent memory

Memory is scoped to your workspace, encrypted at rest, never used to train models, and fully exportable or deletable on request.

Credentials & secrets

3,200+ integrations. Zero secrets in chat.

OAuth-first

Every major tool connects via OAuth with the narrowest scopes that get the job done. No passwords stored.

Encrypted vault

Where API keys are required, they are stored in a secrets vault, AES-256 at rest, isolated from model context, access-logged, and rotatable.

Admin scope control

Admins decide which integrations are connected, who can use them, and at what level. Revoke any integration in one click.

Responsible disclosure

Found something? Tell us.

We would rather hear about an issue from a researcher than read about it on Twitter.

We are building a formal bug bounty program. In the meantime, we recognize meaningful security research with a thank you, public credit if you want it, and Viktor credits.

FAQ

Does Viktor's AI model see our API keys or tokens?

No. Credentials are stored in encrypted vaults and injected at execution time by a backend tool gateway. The AI model never sees them in any context, including planning, execution, or logs.

Is our data used to train AI models?

Can Viktor act without human approval?

How is our workspace isolated from other companies?

Does Viktor read Slack channels or DMs we haven't invited him to?

Can Viktor access our codebase?

Which AI models does Viktor use?

What about prompt-injection attacks?

What compliance documentation is available?

Does Viktor support SSO?

Where is data hosted, and can we choose a region?

How do we delete our data?