Virtualitics · Trust Center

Virtualitics Trust Center

Trust center

Virtualitics maintains a public trust center documenting NIST SP 800-171, CMMC, SOC 2 Type 2, SOC 2 Type 3, CIS Top 20, and FIPS 140-2 compliance.

CompanyArtificial IntelligenceData AnalyticsData VisualizationMachine LearningDefenseGovernmentPythonSDKCommand Line Interface
Trust center:

Certifications & Compliance

NIST SP 800-171CMMCSOC 2 Type 2SOC 2 Type 3CIS Top 20FIPS 140-2

Source

Trust Center

virtualitics-trust-center.yml Raw ↑
generated: '2026-09-04'
method: searched
source: https://virtualitics.com/security/
checked: '2026-09-04'
found: true
trust_center:
  kind: published security page (not a hosted trust portal)
  url: https://virtualitics.com/security/
  dedicated_subdomain: false
  probed:
  - host: trust.virtualitics.com
    result: NXDOMAIN
  note: >-
    Virtualitics does not run a Vanta/Drata/SafeBase-style trust portal. It publishes a single
    first-party security page that names its frameworks and offers a downloadable report, which is
    the substance a buyer needs even without the portal.
certifications:
- name: NIST SP 800-171
  status: compliant
- name: CMMC
  status: ready
- name: SOC 2 Type 2
  status: achieved
  report_available: true
- name: SOC 2 Type 3
  status: in process
  note: >-
    As written on the page. SOC 3 is the public-report form of SOC 2; the page separately offers a
    "Service Organization Control 3 (SOC 3) report" download.
- name: CIS Top 20
  status: listed
- name: FIPS 140-2
  status: claimed (cryptography)
reports_available:
- name: SOC 3 report
  access: download from https://virtualitics.com/security/
- name: SOC 2 Type 2 report
  access: referenced on the security page
control_areas:
  product_security:
  - Continuous internal and external vulnerability scanning
  - Data encryption at rest and in transit
  - Data validation
  - Data retention
  - Data isolation
  - FIPS 140-2 cryptographic compliance
  security_monitoring:
  - Continuous network vulnerability scanning
  - Continuous endpoint security monitoring
  - Continuous cloud security monitoring
  business_resiliency:
  - Business continuity program
  - Disaster recovery testing
  workforce_security:
  - Background checks
  - Security awareness training
  - Continuous phishing email campaigns
government_posture:
  statement: >-
    "strict adherence to US Department of War security requirements and commercial security
    standards and frameworks", validated by "external and independent assessments of our
    cybersecurity risk management program".
  networks: [NIPR, SIPR, JWICS]
  platforms: [ADVANA, ODIN]
  source: https://virtualitics.com/company-overview/
gaps:
- No FedRAMP or StateRAMP authorization is named.
- No ISO/IEC 27001 certification is named.
- No CMVP certificate number is given for the FIPS 140-2 claim.
- No sub-processor list, data-residency statement or pen-test cadence is published.
- No security.txt — see security/virtualitics-vulnerability-disclosure.yml.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/virtualitics-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.