Read-only by default
Assessments run on least-privilege, read-only roles — and we publish the exact permission list each platform requires before we ever request access. We do not modify client configurations during an assessment.
Trust & Security
The questions a procurement team or a vendor-risk reviewer will put to us, answered before you have to ask — including the one most consultancies avoid.
Assessments run on least-privilege, read-only roles — and we publish the exact permission list each platform requires before we ever request access. We do not modify client configurations during an assessment.
Queries execute inside your infrastructure; reports generate on your side of the wall. No client identity data is uploaded to vaultIAM or any third party during analysis.
The consultant you meet is the consultant who does the work. No junior substitution after signature, no offshore delivery team you were not told about.
We execute BAAs for healthcare engagements without friction, and engagement agreements are governed by Ontario law. Insurance certificates are provided during vendor onboarding on request.
Internal access follows least privilege with documented onboarding and offboarding, and every vaultIAM account is protected with multi-factor authentication.
Every engagement agreement includes a written commitment: defined security-incident notification windows, cooperation obligations, and post-incident review participation.
vaultIAM does not hold a SOC 2 Type II report or an ISO 27001 certificate, and is not currently in an audit or certification process for either. We would rather tell you that on a public page than display a badge we cannot evidence — particularly to buyers whose job is verifying exactly this.
What matters more for the engagement shape we actually sell: the assessment is read-only, it runs inside your environment, the permission set is published before we request it, no client identity data is egressed to us, and the people named in the proposal are the people who do the work. Those are the controls a certification would be attesting to, and you can verify each of them directly rather than through an auditor.
If your vendor-risk process requires a certified supplier with no exception path, tell us on the first call. We will say so plainly rather than spend six weeks of your procurement cycle finding out.
One distinction worth being explicit about. Framework names appear throughout this site — SOC 2, HITRUST, PCI DSS, FFIEC, NYDFS, HIPAA, OSFI B-13, PIPEDA, Law 25, PHIPA. Every one of those describes a regime we build and evidence controls against, on client engagements. None of them is a certification vaultIAM holds, and none appears here as a badge, a seal, or a trust mark. Where we can help you satisfy a standard, we say so; where a standard would be a claim about us, we do not make it.
Last updated 24 August 2026
This page is the list. We update it here whenever it changes, and clients under an active engagement are notified directly.
Cal ID
Meeting scheduling
Can see: Name, email, and anything you type into the booking form. The calendar loads only when you ask for it, so visiting our contact page does not contact Cal ID
Web3Forms
Relays Assessment Guide download requests to us by email
Can see: Work email, sector, role, and company if you supplied one
Vercel
Website hosting and analytics
Can see: Request logs; no identifying analytics profile
Zoho Mail
Email and document handling
Can see: Correspondence and engagement documents
None of these subprocessors receive client identity data from an assessment. Assessment queries and their output stay inside your environment.
Vendor-risk questionnaires, insurance certificates, the subprocessor list above, and reference contacts are packaged and available on request at hello@vaultiam.com. Most questionnaires come back within a week; if yours is against a deadline, say so and we will work to it.
You will not find a client count, an "identities under governance" figure, a partner badge, or a certification mark anywhere on this site. Those are performance and certification claims, and under Canadian and US advertising law the burden of substantiating them sits with whoever makes them. We only publish claims we can evidence on request — including every statistic, which carries the publishing organisation and the exact report edition.