Skip to content
omar-flores-vLN225oj0ck-unsplash

SSO and Enterprise Security:Controls Built for Regulated Industries and Large Organizations


For individual users, Vikk AI's default security (TLS 1.3, AES-256, no training on user data) is strong and sufficient. For organizations, security is not just about the data but about the controls around it: who has access, how access is managed, how it integrates with existing identity systems, how it is audited, and how it meets regulatory and compliance requirements. This page covers the enterprise security features available on Vikk AI Business and Enterprise plans.

Single Sign-On (SSO)


SAML 2.0 support

Native SAML 2.0 SSO integration with all major identity providers: Okta, Azure AD (Microsoft Entra), Google Workspace, OneLogin, Ping Identity, Duo, JumpCloud, and custom SAML providers.

Single identity across tools

Users log into Vikk AI with the same corporate credentials they use for email, document storage, and other SaaS tools. Password management, MFA enforcement, and conditional access policies are inherited from your identity provider.

SCIM provisioning

Automated user provisioning and deprovisioning. Users added to the Vikk AI group in your IDP are automatically provisioned with appropriate role and workspace access. Users removed are deprovisioned immediately. No manual user management in the Vikk AI admin console.

Group-based access controls

Map IDP groups to Vikk AI workspaces and roles. Members of the HR group get automatic access to the HR workspace. Members of the Legal group get admin access to the Legal workspace.

Multi-Factor Authentication

MFA required by policy

Enforce MFA for all users, all admins, or specific groups. Enforcement happens at login regardless of the access method (web, mobile, API).

MFA methods

  • TOTP apps (Google Authenticator, Authy, Microsoft Authenticator, 1Password, others).
  • Hardware security keys (YubiKey, Feitian, Titan Security Key, FIDO2-compatible).
  • Backup codes for recovery.
  • SMS MFA supported but not recommended due to SIM-swap risks.

MFA inheritance from IDP

When SSO is configured, MFA is typically enforced at the IDP level, giving you centralized MFA management across all your SaaS tools.

SOC 2 Type II

SOC 2 Type II attestation

Vikk AI maintains SOC 2 Type II posture across the Trust Services Criteria (Security, Availability, Confidentiality). Independent audits are performed annually by a Big Four firm. Reports are available to Business Premium and Enterprise customers under NDA.

Continuous compliance monitoring

Beyond the annual audit, Vikk AI maintains continuous compliance monitoring with automated evidence collection. Changes to the control environment are tracked, and deviations are remediated promptly.

Audit Logging and Monitoring

Comprehensive audit logs

Full audit trail of administratively significant events: user provisioning, login events, policy changes, data deletions, admin actions, and API calls. Logs include timestamp, actor, action, target, and outcome.

Log retention

Business plans: 90 days of audit log retention by default. Enterprise plans: up to 7 years of retention, configurable based on your compliance requirements.

Log export and SIEM integration

Audit logs are exportable in JSON, CSV, and CEF (Common Event Format). Native integrations with major SIEM platforms (Splunk, Datadog, Sumo Logic) are available on Enterprise plans.

User activity insights

Aggregate user activity dashboards for admin visibility into deployment health, usage patterns, and potential anomalies.

Data Retention and Residency


Custom retention policies

Set automatic data retention windows: 30, 90, 180 days, or longer. After the retention period, conversations and documents are automatically deleted.

Per-workspace retention

Different workspaces can have different retention policies. The HR workspace might retain records for 7 years for employment law reasons, while an operational workspace might retain for 90 days.

Data residency

Enterprise customers can specify data residency in U.S., EU, or other specific regions (availability varies). Important for organizations subject to data localization requirements like GDPR, Schrems II considerations, or financial services regulations.

Encryption key management

Default encryption is managed by Vikk AI. Enterprise customers can request customer-managed keys (CMK) for specific regulatory requirements, with Vikk AI maintaining access only for service operations.

Compliance Posture

HIPAA

For healthcare customers, Vikk AI can execute a Business Associate Agreement (BAA) covering the service provider relationship. HIPAA-specific controls (audit logging, encryption, access controls, breach notification) are part of the Enterprise offering.

GDPR and global privacy

GDPR-compliant data handling, including data subject access rights, portability, erasure, and Data Processing Agreements for EU customers. Also compliant with U.S. state privacy laws (CCPA, CPRA, etc.), Canada's PIPEDA, UK GDPR, and Brazil's LGPD.

Financial services

Controls appropriate for financial services deployments including segregated environments, enhanced audit logging, and incident response procedures. Specific deployments can be tailored to meet FINRA, SEC, and banking regulator requirements.

Government

Public sector deployments available with FedRAMP Moderate (in progress) and StateRAMP support. Contact the Business team for specific compliance requirements.

Incident Response


Dedicated security team

Vikk AI maintains an in-house security team with 24/7 incident response capability. Security events are triaged by severity and remediated according to documented procedures.

Customer notification

Enterprise customers are notified of security events affecting their data within documented timeframes (typically 24-72 hours depending on severity and jurisdiction). Notification procedures are documented in Enterprise DPAs.

Penetration testing and red team

Vikk AI's infrastructure is pen-tested regularly by external specialists. Red team engagements validate detection and response capabilities.

Bug bounty

Security researchers are encouraged to responsibly disclose vulnerabilities via the Vikk AI bug bounty program. Qualifying disclosures receive bounties and public recognition.

Frequently Asked Questions

  • Is SOC 2 available on all plans?

    SOC 2 posture applies to Vikk AI's infrastructure regardless of plan. SOC 2 reports are formally available to Business Premium and Enterprise customers under NDA.

  • Can we use our own identity provider for SSO?

    Yes. Vikk AI supports SAML 2.0 and SCIM with essentially any modern identity provider. Custom IDP integrations are supported on Enterprise plans.

  • How long does enterprise security onboarding typically take?

    Standard SSO and SCIM setup typically takes 1-2 weeks for organizations with existing identity infrastructure. Full Enterprise security onboarding (SSO, custom retention, compliance DPAs, integrations) typically takes 2-4 weeks.

  • Is HIPAA compliance available on all plans?

    HIPAA BAA is available on Business Premium and Enterprise. For organizations handling PHI, Enterprise is typically the appropriate tier due to additional controls like custom data retention and residency.

  • Do you support customer-managed encryption keys?

    Yes, for Enterprise deployments. Customer-managed keys are typically required for specific regulatory scenarios and are available with appropriate service configuration.

  • Can we run a security review before purchasing?

    Yes. Vikk AI's Business and Enterprise sales process includes a security review step. We provide SOC 2 reports, security questionnaires, and architecture briefings under NDA. Many large customers complete full vendor security reviews before purchase.

Deploy Vikk AI with enterprise-grade controls. Contact our Business team for a security review.

2026 © Vikk Ai

WEBSITE & SEO by NATIVERANK