Security at a glance
The commitments below apply to every production cloud environment and IT engagement that processes customer data.
Certifications and attestations
Independent assessments held by Variance InfoTech. Full audit reports and certification packages are available under the Documentation tab.
SOC 2 Type II
AttestedComprehensive report issued by an independent AICPA CPA audit firm covering the Trust Services Criteria for Security, Confidentiality, and Availability.
HIPAA Compliant
CompliantStrict physical and technical safeguards for Protected Health Information (PHI). Data Processing Agreements and Business Associate Agreements (BAA) available on request.
Reporting a security issue
If you believe you have discovered a potential security vulnerability in Variance InfoTech's applications, client portals, or managed infrastructure, please report it immediately to our security and compliance team. We acknowledge reports within two business days and will keep you updated throughout triage and remediation. Please practice responsible disclosure and do not disclose the issue publicly until a verified fix is deployed.
Security Documentation
Audit reports and sensitive policy documents are shared with customers and prospective enterprise partners under mutual NDA. Public artefacts can be viewed directly.
Security Controls
A summary of the technical, administrative, and organizational controls we operate across our platforms and services. Full control statements are covered in our SOC 2 and ISO 27001 Statement of Applicability.
Security starts during development—not after deployment.
We design and operate technology environments with security, availability, and resilience in mind.
Only the right people should have access to the right systems.
Access to customer environments and source code follows defined roles and least-privilege principles.
MFA is mandatory across staff, contractors, repositories, and cloud management environments.
Enterprise identity environments can use SAML 2.0 and OpenID Connect.
Access permissions are reviewed periodically, with privileged accounts receiving additional oversight.
Joiner, mover, and leaver processes help ensure access is granted, modified, or revoked appropriately.
Administrative activity, server access, and database operations are logged and monitored.
Security requires continuous visibility—not occasional checks.
Business-critical systems need to remain resilient when unexpected events occur.
As businesses increasingly adopt Generative AI, AI Agents, RAG, LLMs, AI Copilots, and intelligent
automation, protecting AI workflows becomes equally important.
Variance Infotech incorporates security and governance considerations into AI implementations.
AI recommendations and insights support business users while critical operational and domain decisions remain under human control.
Customer code, prompts, call audio, proprietary documents, and other customer information are not fed into public foundational model training.
AI systems can be evaluated for hallucinations, toxicity, bias, and other risks.
Enterprise AI implementations can provide supporting evidence and citations where applicable.
AI applications are integrated with defined business rules, APIs, access controls, and system boundaries rather than being given unrestricted access to business systems.
Healthcare applications require additional attention to privacy, access, data handling, and
auditability.
Our technology portfolio includes healthcare and dental solutions, healthcare CRM, patient management
systems, dental management systems, and dental software integrations.
For engagements involving Protected Health Information (PHI), our Trust Center states that Variance
Infotech implements HIPAA-compliant security architectures and supports formal Business Associate
Agreements (BAAs).
Security is particularly important when multiple platforms, applications, APIs, and data sources are connected.
AI & Generative AI
- AI Applications
- AI Agents
- AI Chatbots
- RAG
- LLM Development
- AI Copilots
- Generative AI Integration
- AI Workflow Automation
- Computer Vision
- Machine Learning
CRM & Enterprise Platforms
- Salesforce
- SuiteCRM
- CRM Integrations
- Enterprise CRM Solutions
- Healthcare CRM
- Telecom CRM
- Travel CRM
- Education CRM
- Call Center CRM
Enterprise Integrations
- Salesforce integrations
- WhatsApp integrations
- Telephony integrations
- Open Dental to GoHighLevel
- Dentrix to GoHighLevel
- Outlook integrations
- MindBody integrations
- Zillow integrations
Cloud & DevOps
- AWS
- Azure
- DigitalOcean
- DevOps
- AIOps
- Kubernetes
- Docker
- Cloud migration
- SRE
- LLM Observability
Security Across Our Technology Ecosystem
Security is particularly important when multiple platforms, applications, APIs, and data sources are connected. This breadth makes security an important part of every integration and development decision across our solution portfolio.
AI & Generative AI
11 Capabilities| Solutions & Platforms | Security & Governance Approach |
|---|---|
| AI Applications & AI Agents | Sandboxed execution boundaries, rate limiting, and business-rule validation before system actions. |
| AI Chatbots & AI Copilots | Human oversight guardrails, automated content moderation, hallucination mitigation, and explainability. |
| RAG & LLM Development | Zero public foundational model training on customer data; encrypted private vector stores and RBAC filtering. |
| Generative AI Integration & AI Workflow Automation | Secured API gateways, TLS 1.3 transit encryption, credential isolation, and strict input/output sanitization. |
| Computer Vision & Machine Learning | Dedicated VPC inference endpoints, controlled model artifact storage, and privacy-preserving data processing. |
CRM & Enterprise Platforms
9 Solutions| Platforms & Systems | Security & Compliance Controls |
|---|---|
| Salesforce & SuiteCRM | OAuth 2.0 / SAML identity integration, granular profile and field-level permissions, and immutable audit logs. |
| CRM Integrations & Enterprise CRM Solutions | API least-privilege tokens, encrypted webhook pipelines, rate-limiting, and error-handling logging safeguards. |
| Healthcare CRM | HIPAA-compliant security architecture, BAA execution, PHI encryption at rest (AES-256) and in transit (TLS 1.3). |
| Telecom, Travel & Education CRM | Multi-tenant data isolation, GDPR/PII masking, and role-based operational access boundaries. |
| Call Center CRM | Encrypted telephony streams, voice recording PII redacting, and secure CTI protocol integration. |
Enterprise Integrations
8 Integrations| Integration Services | Integration Security & Transport Standards |
|---|---|
| Open Dental to GoHighLevel | HIPAA-compliant middleware sync pipelines, end-to-end encryption, and automated sensitive dental data safeguards. |
| Dentrix to GoHighLevel | Secure encrypted sync bridge, access audits, zero local caching of unencrypted PHI, and token authentication. |
| Salesforce Integrations | Certified REST/SOAP API connectors, mutual TLS, scoped access permissions, and automated webhook retries. |
| WhatsApp & Telephony Integrations | End-to-end encrypted messaging channels, webhook signature verification, and carrier API security. |
| Outlook, MindBody & Zillow Integrations | Enterprise OAuth 2.0 authorization, minimal data scope grants, and encrypted cloud synchronization. |
Cloud & DevOps
10 Core Practices| Environment & Tooling | Infrastructure Security & Reliability Role |
|---|---|
| AWS, Azure & DigitalOcean | VPC network segregation, private subnets, security groups, and automated encrypted backups across regions. |
| Kubernetes & Docker | Container image vulnerability scanning, least-privilege service accounts, and automated pod health checks. |
| DevOps & AIOps | Secure CI/CD pipelines, automated SAST/dependency scanning, Software Bill of Materials (SBOM), and alerts. |
| Cloud Migration & SRE | Zero-data-loss migration playbooks, high-availability architecture, and targeted RTO 4h / RPO 1h resilience. |
| LLM Observability | Continuous model telemetry, prompt injection detection, token usage auditing, and response quality monitoring. |
Frequently Asked Questions
Answers to common enterprise security, compliance, data handling, and procurement questions.
Yes. Yes. Security is incorporated into application development, cloud infrastructure, data handling, access management, monitoring, incident response, and AI governance practices.
Yes. The Trust Center states that data at rest is protected using AES-256 encryption and data in transit using TLS 1.2 or TLS 1.3..
No. The Trust Center states that customer code, database assets, voice recordings, transcripts, and proprietary client documents are not used to train or fine-tune public foundation AI models.
For healthcare, dental, and telehealth engagements involving PHI, the Trust Center states that Variance Infotech implements HIPAA-compliant security architectures and supports formal BAAs.
The Trust Center identifies SOC 2 Type II as an attestation and provides a process for requesting the report.
Yes. Security and compliance documentation can be requested through the Trust Center and security team. Certain sensitive documents are provided under NDA.
Yes. The Trust Center states that the compliance team supports SIG, CAIQ, VSA, and customized internal procurement security assessments.
Yes.Yes. The Trust Center states that customers can request complete deletion of their data, including upon contract termination, subject to the applicable contractual process.
Variance Infotech maintains a documented incident-response framework covering detection, containment, eradication, recovery, and post-mortem activities.
Visit the Variance Infotech Trust Center for the detailed security controls, documentation, subprocessors, FAQs, and compliance information.