Physical infrastructure
Globally distributed data centers with strict physical controls, power redundancy, fire detection and suppression, and continuous surveillance, operated directly by the platforms.
Every Vantegrate deployment runs 100% on Salesforce or on Oracle Cloud Infrastructure (OCI). The SOC 2 Type II and ISO 27001 reports that protect your data belong to those platforms, not to us. We think that is exactly what a CISO should want to hear.
99.99%
Uptime SLA
AES-256
Encryption at rest
SOC 2
Controls audit
ISO 27001
Security management
PCI DSS
Protected payments
GDPR
European privacy
HIPAA
Health data
The honest answer
Most AI vendors lead with a wall of badges. We lead with a clarification.
Vantegrate does not operate infrastructure of its own. Every agent we deliver runs entirely inside Salesforce or Oracle Cloud Infrastructure, so the certifications that matter, SOC 2 Type II, ISO 27001/27017/27018/27701, PCI DSS and GDPR alignment, belong to those platforms and are inherited by your deployment from day one.
When you evaluate a SOC 2 AI vendor, the real question is where the controls actually live. A startup's own report covers its offices and laptops; the controls that protect your CRM data are the platform's. Because everything runs on the platform, your data never leaves an environment that is already audited, and there is no middleware copy for an attacker to find.
Our formula is simple: the platform certifies, Vantegrate enables, your team operates. We configure the native security model around each agent; you keep ownership of the data, the governance and the audit trail.
What your deployment inherits
Inherited from Salesforce or OCI. Verifiable on their public compliance portals, no NDA required.
The agentic gap
CISOs are not slowing AI down; they are the reason it ships. The distance between experimenting with AI agents and running them in production is, above all, a trust gap.
85%
Of enterprises were already experimenting with AI agents
Source: Cisco enterprise AI survey (2025)
5%
Had taken agentic AI all the way to production in the same survey
Source: Cisco enterprise AI survey (2025)
Inherited controls
Building on Salesforce or Oracle Cloud means day one starts with controls that would take years to stand up internally. These run at the platform layer, underneath every Vantegrate agent.
Globally distributed data centers with strict physical controls, power redundancy, fire detection and suppression, and continuous surveillance, operated directly by the platforms.
AES-256 for data at rest and TLS for data in transit, enabled by default on both platforms. Cryptographic protection is active from the first minute.
DDoS mitigation, continuous traffic monitoring, perimeter firewalls, redundant load balancers and multi-provider connectivity, all managed by the platform teams.
Salesforce and Oracle both run global detection, response and forensics teams that watch the platform runtime around the clock.
Both platforms run regular vulnerability assessments and penetration tests on their infrastructure, validated by independent third parties.
Public service status pages, incident history, scheduled maintenance windows and availability SLAs published by each platform.
Compliance
These certifications correspond to the platforms Vantegrate runs on. You do not have to take our word for any of them: verify them yourself on the official Salesforce compliance portal and the Oracle cloud compliance site.
Independent third-party audits of the security, availability and confidentiality controls of the environment, renewed continuously.
International standards for information security management, cloud-specific controls and protection of personal data in cloud services.
Privacy information management: the extension that governs how personal data is handled in processor and controller roles.
Alignment with the EU General Data Protection Regulation, with data processing agreements available for your legal review.
The most demanding standard for handling payment card information securely.
Frameworks the platforms maintain for protected health information and for United States federal government workloads.
Governance
An agent is a governed identity in your org, not a black box. The same access, permission and audit model that governs your people governs every Vantegrate agent.
Shared responsibility
Real security is a joint effort, and pretending otherwise is marketing. This is how responsibility splits in a Vantegrate deployment.
THE PLATFORM
Salesforce or Oracle
VANTEGRATE
Enables
YOUR COMPANY
Operates and certifies
Per product
Each product inherits the platform controls and adds safeguards specific to its job.
Data residency
"Where is my data stored?" is the first question we get from security teams. The answer is concrete: in your platform tenant, in the region you contract.
Your data lives in your Salesforce instance or your OCI tenancy, in the region defined when the environment is provisioned. Vantegrate does not replicate it to infrastructure of its own, because we do not operate any.
Because the platform hosts the data, it is processed under the regulatory frameworks both vendors cover globally, including GDPR in the European Union and LGPD in Brazil, plus the sector-specific United States regimes the platforms support.
Vantegrate does not use your organization's data for any purpose other than delivering the contracted service. No training on your data, no secondary use, no exceptions.
The region where your data resides depends on the platform and instance you contract. We advise you during provisioning, including OCI region selection for strict residency mandates.
We sign DPAs with clients that require them and facilitate the platform DPAs for your legal review.
Retention policies are defined inside your environment, to your regulatory and business requirements.
Straight answers to the questions security teams raise in due diligence.
They are as secure as the infrastructure and the governance around them, which is why architecture is the first thing to check. Vantegrate agents run entirely inside Salesforce or Oracle Cloud Infrastructure: data never leaves the audited environment, every action respects your existing permission model, and the full audit trail stays in your tenant. There is no Vantegrate-operated middleware holding a copy of your data.
Honest answer: the SOC 2 Type II reports that cover your deployment belong to Salesforce and Oracle, not to Vantegrate. We run 100% on their infrastructure, so your deployment inherits those audited controls instead of depending on a vendor-grade report. Your auditors can verify every certification directly on the platforms' public compliance portals, and we support that review.
Through the platform's native security model, the same one that governs your human users. Each agent operates under profiles, permission sets, visibility rules and field-level security that you define and can revoke at any time. Logins, configuration changes and agent actions are logged, so governance reviews and audits use the trail you already own.
In your own Salesforce instance or Oracle Cloud (OCI) tenancy, in the region selected when the environment is provisioned. Vantegrate does not copy your data to external infrastructure. If you have strict data residency requirements, the OCI model lets you pin the deployment to a specific region, and we advise on that choice during provisioning.
35+ direct integrations
We run a technical session with your CISO, IT lead or whoever you designate. Concrete answers, the architecture on the platform that fits your case, and the documentation your review requires.