Single Sign-On (SSO)
SAML 2.0 support
Native SAML 2.0 SSO integration with all major identity providers: Okta, Azure AD (Microsoft Entra), Google Workspace, OneLogin, Ping Identity, Duo, JumpCloud, and custom SAML providers.
Single identity across tools
Users log into Vikk AI with the same corporate credentials they use for email, document storage, and other SaaS tools. Password management, MFA enforcement, and conditional access policies are inherited from your identity provider.
SCIM provisioning
Automated user provisioning and deprovisioning. Users added to the Vikk AI group in your IDP are automatically provisioned with appropriate role and workspace access. Users removed are deprovisioned immediately. No manual user management in the Vikk AI admin console.
Group-based access controls
Map IDP groups to Vikk AI workspaces and roles. Members of the HR group get automatic access to the HR workspace. Members of the Legal group get admin access to the Legal workspace.
Multi-Factor Authentication
Audit Logging and Monitoring
Data Retention and Residency
Custom retention policies
Set automatic data retention windows: 30, 90, 180 days, or longer. After the retention period, conversations and documents are automatically deleted.
Per-workspace retention
Different workspaces can have different retention policies. The HR workspace might retain records for 7 years for employment law reasons, while an operational workspace might retain for 90 days.
Data residency
Enterprise customers can specify data residency in U.S., EU, or other specific regions (availability varies). Important for organizations subject to data localization requirements like GDPR, Schrems II considerations, or financial services regulations.
Encryption key management
Default encryption is managed by Vikk AI. Enterprise customers can request customer-managed keys (CMK) for specific regulatory requirements, with Vikk AI maintaining access only for service operations.
Compliance Posture
Incident Response
Dedicated security team
Vikk AI maintains an in-house security team with 24/7 incident response capability. Security events are triaged by severity and remediated according to documented procedures.
Customer notification
Enterprise customers are notified of security events affecting their data within documented timeframes (typically 24-72 hours depending on severity and jurisdiction). Notification procedures are documented in Enterprise DPAs.
Penetration testing and red team
Vikk AI's infrastructure is pen-tested regularly by external specialists. Red team engagements validate detection and response capabilities.
Bug bounty
Security researchers are encouraged to responsibly disclose vulnerabilities via the Vikk AI bug bounty program. Qualifying disclosures receive bounties and public recognition.
Frequently Asked Questions
-
Is SOC 2 available on all plans?
SOC 2 posture applies to Vikk AI's infrastructure regardless of plan. SOC 2 reports are formally available to Business Premium and Enterprise customers under NDA.
-
Can we use our own identity provider for SSO?
Yes. Vikk AI supports SAML 2.0 and SCIM with essentially any modern identity provider. Custom IDP integrations are supported on Enterprise plans.
-
How long does enterprise security onboarding typically take?
Standard SSO and SCIM setup typically takes 1-2 weeks for organizations with existing identity infrastructure. Full Enterprise security onboarding (SSO, custom retention, compliance DPAs, integrations) typically takes 2-4 weeks.
-
Is HIPAA compliance available on all plans?
HIPAA BAA is available on Business Premium and Enterprise. For organizations handling PHI, Enterprise is typically the appropriate tier due to additional controls like custom data retention and residency.
-
Do you support customer-managed encryption keys?
Yes, for Enterprise deployments. Customer-managed keys are typically required for specific regulatory scenarios and are available with appropriate service configuration.
-
Can we run a security review before purchasing?
Yes. Vikk AI's Business and Enterprise sales process includes a security review step. We provide SOC 2 reports, security questionnaires, and architecture briefings under NDA. Many large customers complete full vendor security reviews before purchase.
Deploy Vikk AI with enterprise-grade controls. Contact our Business team for a security review.
Are you a Lawyer? Connect with our Users!