Trust Center

Secure AI agents on enterprise infrastructureCertified by the platform

Every Vantegrate deployment runs 100% on Salesforce or on Oracle Cloud Infrastructure (OCI). The SOC 2 Type II and ISO 27001 reports that protect your data belong to those platforms, not to us. We think that is exactly what a CISO should want to hear.

99.99%

Uptime SLA

AES-256

Encryption at rest

SOC 2

Controls audit

ISO 27001

Security management

PCI DSS

Protected payments

GDPR

European privacy

HIPAA

Health data

The honest answer

Whose certifications protect your data? The platform's. By design.

Most AI vendors lead with a wall of badges. We lead with a clarification.

Vantegrate does not operate infrastructure of its own. Every agent we deliver runs entirely inside Salesforce or Oracle Cloud Infrastructure, so the certifications that matter, SOC 2 Type II, ISO 27001/27017/27018/27701, PCI DSS and GDPR alignment, belong to those platforms and are inherited by your deployment from day one.

When you evaluate a SOC 2 AI vendor, the real question is where the controls actually live. A startup's own report covers its offices and laptops; the controls that protect your CRM data are the platform's. Because everything runs on the platform, your data never leaves an environment that is already audited, and there is no middleware copy for an attacker to find.

Our formula is simple: the platform certifies, Vantegrate enables, your team operates. We configure the native security model around each agent; you keep ownership of the data, the governance and the audit trail.

What your deployment inherits

  • SOC 2 Type II audited controls, renewed continuously
  • ISO 27001 / 27017 / 27018 / 27701 certifications
  • GDPR alignment with data processing agreements available
  • Data residency tied to your platform region, not to a vendor cloud
  • PCI DSS Level 1, HIPAA and FedRAMP frameworks at the platform layer

Inherited from Salesforce or OCI. Verifiable on their public compliance portals, no NDA required.

The agentic gap

Security is what separates AI pilots from production

CISOs are not slowing AI down; they are the reason it ships. The distance between experimenting with AI agents and running them in production is, above all, a trust gap.

85%

Of enterprises were already experimenting with AI agents

Source: Cisco enterprise AI survey (2025)

5%

Had taken agentic AI all the way to production in the same survey

Source: Cisco enterprise AI survey (2025)

Inherited controls

The security that is already built

Building on Salesforce or Oracle Cloud means day one starts with controls that would take years to stand up internally. These run at the platform layer, underneath every Vantegrate agent.

Physical infrastructure

Globally distributed data centers with strict physical controls, power redundancy, fire detection and suppression, and continuous surveillance, operated directly by the platforms.

Encryption by default

AES-256 for data at rest and TLS for data in transit, enabled by default on both platforms. Cryptographic protection is active from the first minute.

Network protection

DDoS mitigation, continuous traffic monitoring, perimeter firewalls, redundant load balancers and multi-provider connectivity, all managed by the platform teams.

Incident response

Salesforce and Oracle both run global detection, response and forensics teams that watch the platform runtime around the clock.

Penetration testing

Both platforms run regular vulnerability assessments and penetration tests on their infrastructure, validated by independent third parties.

Continuity and availability

Public service status pages, incident history, scheduled maintenance windows and availability SLAs published by each platform.

Compliance

Platform certifications, publicly verifiable

These certifications correspond to the platforms Vantegrate runs on. You do not have to take our word for any of them: verify them yourself on the official Salesforce compliance portal and the Oracle cloud compliance site.

SOC 1 / SOC 2 Type II / SOC 3

Independent third-party audits of the security, availability and confidentiality controls of the environment, renewed continuously.

ISO 27001 / 27017 / 27018

International standards for information security management, cloud-specific controls and protection of personal data in cloud services.

ISO 27701

Privacy information management: the extension that governs how personal data is handled in processor and controller roles.

GDPR

Alignment with the EU General Data Protection Regulation, with data processing agreements available for your legal review.

PCI DSS Level 1

The most demanding standard for handling payment card information securely.

HIPAA / FedRAMP

Frameworks the platforms maintain for protected health information and for United States federal government workloads.

Governance

AI agent governance runs on your terms

An agent is a governed identity in your org, not a black box. The same access, permission and audit model that governs your people governs every Vantegrate agent.

Identity and access

  • Multi-factor authentication (MFA) configurable for every user and integration
  • Single Sign-On (SSO) against your corporate identity provider
  • IP range restrictions that limit access to authorized networks
  • Session timeouts aligned with your internal policy

Permission model

  • Granular permissions per user and per role, agents included
  • Visibility rules that define who sees which records
  • Field-level security that hides sensitive data, even from the agent
  • Segregation of duties across operators, supervisors and administrators

Traceability and audit

  • Change history on every relevant record
  • Logs of logins, configuration changes and administrative actions
  • Every agent action attributable and reviewable in your own trail
  • Advanced audit services and extra encryption available per platform

Shared responsibility

Who does what in the security chain

Real security is a joint effort, and pretending otherwise is marketing. This is how responsibility splits in a Vantegrate deployment.

THE PLATFORM

Salesforce or Oracle

  • Physical and logical infrastructure
  • Encryption in transit and at rest
  • Data centers and availability
  • Monitoring and incident response
  • Penetration testing of the runtime

VANTEGRATE

Enables

  • Secure design of the AI agents
  • Configuration of the permission model
  • Platform security best practices applied
  • Integrations with external services
  • Hands-on support through go-live

YOUR COMPANY

Operates and certifies

  • MFA enforcement for your users
  • Definition of your access policies
  • Approval of each agent's scope
  • Training for your team
  • Monitoring of user and agent activity

Per product

How this applies to every Vantegrate agent

Each product inherits the platform controls and adds safeguards specific to its job.

Sellium, Conversational sales agent

  • Conversations, contacts and deal context stay inside your implementation's infrastructure
  • WhatsApp Business integration through Meta's official authorized providers
  • Every interaction traceable in the platform's native history

Revio, WhatsApp marketing campaigns

  • Contact lists and consent records managed inside the platform
  • Compliance with WhatsApp Business policies for outbound campaigns
  • Send and response reports consolidated in your secure environment

Arconte, Intelligent document processing

  • Documents stored in your platform's ecosystem, with encryption at rest
  • Access permissions per user and per folder under the native model
  • Extraction runs with the platform's controls applied to the extracted data

Metrix, Conversational business intelligence

  • Queries automatically respect each user's permissions in the source platform: people only see data they already had access to
  • Field-level security applies transparently: restricted data is never exposed, not even to the analytics engine
  • Every query lands in the audit history

Trazzo, Last-mile logistics optimization

  • Operational data (routes, stops, drivers) managed inside your platform
  • Maps and geolocation services connected over encrypted channels
  • Differentiated permissions for operators, supervisors and administrators

Data residency

Data residency for AI agents, answered precisely

"Where is my data stored?" is the first question we get from security teams. The answer is concrete: in your platform tenant, in the region you contract.

Your data lives in your Salesforce instance or your OCI tenancy, in the region defined when the environment is provisioned. Vantegrate does not replicate it to infrastructure of its own, because we do not operate any.

Because the platform hosts the data, it is processed under the regulatory frameworks both vendors cover globally, including GDPR in the European Union and LGPD in Brazil, plus the sector-specific United States regimes the platforms support.

Vantegrate does not use your organization's data for any purpose other than delivering the contracted service. No training on your data, no secondary use, no exceptions.

Data residency

The region where your data resides depends on the platform and instance you contract. We advise you during provisioning, including OCI region selection for strict residency mandates.

Data processing agreements

We sign DPAs with clients that require them and facilitate the platform DPAs for your legal review.

Data retention

Retention policies are defined inside your environment, to your regulatory and business requirements.

Frequently asked questions

What CISOs ask us about secure AI agents

Straight answers to the questions security teams raise in due diligence.

Are AI agents secure for enterprise data?

They are as secure as the infrastructure and the governance around them, which is why architecture is the first thing to check. Vantegrate agents run entirely inside Salesforce or Oracle Cloud Infrastructure: data never leaves the audited environment, every action respects your existing permission model, and the full audit trail stays in your tenant. There is no Vantegrate-operated middleware holding a copy of your data.

Is Vantegrate SOC 2 compliant?

Honest answer: the SOC 2 Type II reports that cover your deployment belong to Salesforce and Oracle, not to Vantegrate. We run 100% on their infrastructure, so your deployment inherits those audited controls instead of depending on a vendor-grade report. Your auditors can verify every certification directly on the platforms' public compliance portals, and we support that review.

How do I govern what an AI agent can access?

Through the platform's native security model, the same one that governs your human users. Each agent operates under profiles, permission sets, visibility rules and field-level security that you define and can revoke at any time. Logins, configuration changes and agent actions are logged, so governance reviews and audits use the trail you already own.

Where is my data stored when I deploy an AI agent?

In your own Salesforce instance or Oracle Cloud (OCI) tenancy, in the region selected when the environment is provisioned. Vantegrate does not copy your data to external infrastructure. If you have strict data residency requirements, the OCI model lets you pin the deployment to a specific region, and we advise on that choice during provisioning.

35+ direct integrations

SalesforceMercado PagoOpenpayPaywayOracleServiceNowSlackSAPStripeFiservSalesforce Marketing CloudMicrosoft Dynamics 365HubSpotWhatsApp BusinessSalesforceMercado PagoOpenpayPaywayOracleServiceNowSlackSAPStripeFiservSalesforce Marketing CloudMicrosoft Dynamics 365HubSpotWhatsApp Business

Put this architecture in front of your security team

We run a technical session with your CISO, IT lead or whoever you designate. Concrete answers, the architecture on the platform that fits your case, and the documentation your review requires.

Salesforce
ISV Partner
AppExchange Partner
Salesforce · Since 2009
Oracle
OCI Partner
Marketplace & OCI Partner
Oracle Cloud Infrastructure