Pioneer in Offering CRM Solutions since 2010...

Variance Logo
Contact Us
Variance InfoTech Security & Compliance Portal

Variance InfoTech Trust Center

We treat customer data with enterprise-grade confidentiality and security. This portal outlines our security postures, regulatory compliance (SOC 2 Type II, HIPAA), internal controls, verified subprocessors, and how to request formal audit packages.

Last Updated
01 September 2026
Next Review
01 July 2027
Certifications
SOC 2 Type II, HIPAA
Security Contact
SOC 2 Type II SOC 2 Type II HIPAA Compliant HIPAA Compliant

Security at a glance

The commitments below apply to every production cloud environment and IT engagement that processes customer data.

Encryption at rest
AES-256
Encryption in transit
TLS 1.2 / 1.3
Multi-Factor Authentication
Mandatory
Access Management
RBAC + Least Privilege
Identity
SSO / SAML / OpenID Connect
Penetration Testing
Annual third-party testing
Security Training
Ongoing security awareness
Backups
Encrypted automated backups
Monitoring
Continuous monitoring and alerting
Secure Development
Security-focused SDLC
Vulnerability Management
Defined remediation timelines
Incident Response
Documented response framework
AI Governance
Human oversight and AI guardrails
Business Continuity
DR and resilience planning

Certifications and attestations

Independent assessments held by Variance InfoTech. Full audit reports and certification packages are available under the Documentation tab.

SOC 2 Type II

Attested

Comprehensive report issued by an independent AICPA CPA audit firm covering the Trust Services Criteria for Security, Confidentiality, and Availability.

HIPAA Compliant

Compliant

Strict physical and technical safeguards for Protected Health Information (PHI). Data Processing Agreements and Business Associate Agreements (BAA) available on request.

Reporting a security issue

If you believe you have discovered a potential security vulnerability in Variance InfoTech's applications, client portals, or managed infrastructure, please report it immediately to our security and compliance team. We acknowledge reports within two business days and will keep you updated throughout triage and remediation. Please practice responsible disclosure and do not disclose the issue publicly until a verified fix is deployed.

Security Documentation

Audit reports and sensitive policy documents are shared with customers and prospective enterprise partners under mutual NDA. Public artefacts can be viewed directly.

Certifications and audit reports
SOC 2 Type II report
Latest observation period audit report conducted by an accredited third-party CPA firm.
Under NDA Request access
Penetration test summary
Executive summary of latest third-party application and cloud network penetration test.
Under NDA Request access
CSA STAR / CAIQ Questionnaire
Consensus Assessments Initiative Questionnaire published through the Cloud Security Alliance.
Publicly available Open
Privacy and data protection
Data Processing Agreement (DPA)
Standard enterprise DPA template including EU/UK Standard Contractual Clauses (SCCs).
Under NDA Request access
Privacy Policy
Public privacy notice outlining customer rights, data collection boundaries, and GDPR terms.
Publicly available Open
Subprocessor list
Current authorized cloud and service subprocessors with role descriptions and data centers.
Publicly available
Records of Processing (ROPA)
Article 30 GDPR processing records covering customer assets and data pipelines.
Under NDA Request access
Policies and governance
Information Security Policy (ISP)
Executive summary of enterprise security governance, encryption, and cryptographic standards.
Under NDA Request access
Business Continuity and DR Plan
Disaster recovery operational framework, annual simulation results, and failover metrics.
Under NDA Request access
Incident Response Plan
Documented security incident escalation framework, containment protocol, and notification SLAs.
Under NDA Request access
Cyber Insurance Certificate
Proof of active Cyber Liability & Professional Indemnity insurance policy coverage.
Under NDA Request access
Gated Document Access: Gated audit reports and certificates are released following verification by our compliance team, typically within two business days, and are subject to a mutual non-disclosure agreement.

Security Controls

A summary of the technical, administrative, and organizational controls we operate across our platforms and services. Full control statements are covered in our SOC 2 and ISO 27001 Statement of Applicability.

We apply controls designed to protect customer and business data throughout its lifecycle.

Our approach includes:
Data minimization
Controlled data processing
PII and sensitive-data masking
PHI handling controls
Encryption at rest
Encryption in transit
Data retention controls
Secure data deletion
Customer data ownership
Protected non-production environments
Customer data is not used to train public machine learning models without explicit written consent. Customer data remains within the scope required to deliver the contracted services.

Security starts during development—not after deployment.

Our secure development practices include:
Secure Software Development Lifecycle practices
OWASP Top 10 guidelines
Peer code reviews
Automated code and dependency scanning
Software Bill of Materials (SBOM)
Container vulnerability scanning
Security acceptance criteria
Controlled production releases
QA and automated testing
Rollback procedures
Secrets management
Vulnerability remediation processes
Third-party penetration testing
These practices help integrate security into the development process across custom software, APIs, AI applications, CRM solutions, integrations, and enterprise platforms.

We design and operate technology environments with security, availability, and resilience in mind.

Our infrastructure security approach includes:
Secure cloud hosting
Network segmentation
VPCs and controlled subnets
Security groups
Encrypted databases and storage
Secure key management
Protected production environments
Automated encrypted backups
Geo-redundant recovery
Infrastructure monitoring
High-availability architecture
Variance Infotech's Trust Center identifies AWS, Microsoft Azure, and DigitalOcean as cloud infrastructure environments used across its solutions and services.

Only the right people should have access to the right systems.

Our access-control practices include:
Role-Based Access Control

Access to customer environments and source code follows defined roles and least-privilege principles.

Multi-Factor Authentication

MFA is mandatory across staff, contractors, repositories, and cloud management environments.

Single Sign-On

Enterprise identity environments can use SAML 2.0 and OpenID Connect.

Access Reviews

Access permissions are reviewed periodically, with privileged accounts receiving additional oversight.

Employee Lifecycle Controls

Joiner, mover, and leaver processes help ensure access is granted, modified, or revoked appropriately.

Privileged Session Monitoring

Administrative activity, server access, and database operations are logged and monitored.

Security requires continuous visibility—not occasional checks.

Our security operations include:
Centralized application and infrastructure logging
Continuous monitoring
Automated security alerts
Audit trails
Privileged-access monitoring
Incident response procedures
Security investigation support
Containment and remediation processes
Post-incident review
Regular incident-response exercises
Verified incidents affecting customer data are handled according to applicable contractual notification requirements.

Business-critical systems need to remain resilient when unexpected events occur.

Our approach includes:
High-availability infrastructure
Multi-zone deployment
Automated health checks
Failover mechanisms
Encrypted backups
Point-in-time recovery
Disaster recovery planning
Recovery testing
Capacity planning
Business continuity procedures
The Trust Center currently identifies a target RTO of 4 hours and RPO of 1 hour for critical production tiers.

As businesses increasingly adopt Generative AI, AI Agents, RAG, LLMs, AI Copilots, and intelligent automation, protecting AI workflows becomes equally important.
Variance Infotech incorporates security and governance considerations into AI implementations.

Our Responsible AI Approach
Human Oversight

AI recommendations and insights support business users while critical operational and domain decisions remain under human control.

Data Protection

Customer code, prompts, call audio, proprietary documents, and other customer information are not fed into public foundational model training.

AI Guardrails

AI systems can be evaluated for hallucinations, toxicity, bias, and other risks.

Explainability

Enterprise AI implementations can provide supporting evidence and citations where applicable.

Controlled AI Workflows

AI applications are integrated with defined business rules, APIs, access controls, and system boundaries rather than being given unrestricted access to business systems.

Healthcare applications require additional attention to privacy, access, data handling, and auditability.
Our technology portfolio includes healthcare and dental solutions, healthcare CRM, patient management systems, dental management systems, and dental software integrations.
For engagements involving Protected Health Information (PHI), our Trust Center states that Variance Infotech implements HIPAA-compliant security architectures and supports formal Business Associate Agreements (BAAs).

Security considerations can include:
PHI protection
Encryption
Access controls
Audit trails
Secure integrations
Data minimization
Controlled retention
Secure deletion
Administrative safeguards
Technical safeguards

Security is particularly important when multiple platforms, applications, APIs, and data sources are connected.

Our technology and solution portfolio includes:

AI & Generative AI

  • AI Applications
  • AI Agents
  • AI Chatbots
  • RAG
  • LLM Development
  • AI Copilots
  • Generative AI Integration
  • AI Workflow Automation
  • Computer Vision
  • Machine Learning

CRM & Enterprise Platforms

  • Salesforce
  • SuiteCRM
  • CRM Integrations
  • Enterprise CRM Solutions
  • Healthcare CRM
  • Telecom CRM
  • Travel CRM
  • Education CRM
  • Call Center CRM

Enterprise Integrations

  • Salesforce integrations
  • WhatsApp integrations
  • Telephony integrations
  • Open Dental to GoHighLevel
  • Dentrix to GoHighLevel
  • Outlook integrations
  • MindBody integrations
  • Zillow integrations

Cloud & DevOps

  • AWS
  • Azure
  • DigitalOcean
  • DevOps
  • AIOps
  • Kubernetes
  • Docker
  • Cloud migration
  • SRE
  • LLM Observability

Security Across Our Technology Ecosystem

Security is particularly important when multiple platforms, applications, APIs, and data sources are connected. This breadth makes security an important part of every integration and development decision across our solution portfolio.

AI & Generative AI

11 Capabilities
Solutions & Platforms Security & Governance Approach
AI Applications & AI Agents Sandboxed execution boundaries, rate limiting, and business-rule validation before system actions.
AI Chatbots & AI Copilots Human oversight guardrails, automated content moderation, hallucination mitigation, and explainability.
RAG & LLM Development Zero public foundational model training on customer data; encrypted private vector stores and RBAC filtering.
Generative AI Integration & AI Workflow Automation Secured API gateways, TLS 1.3 transit encryption, credential isolation, and strict input/output sanitization.
Computer Vision & Machine Learning Dedicated VPC inference endpoints, controlled model artifact storage, and privacy-preserving data processing.

CRM & Enterprise Platforms

9 Solutions
Platforms & Systems Security & Compliance Controls
Salesforce & SuiteCRM OAuth 2.0 / SAML identity integration, granular profile and field-level permissions, and immutable audit logs.
CRM Integrations & Enterprise CRM Solutions API least-privilege tokens, encrypted webhook pipelines, rate-limiting, and error-handling logging safeguards.
Healthcare CRM HIPAA-compliant security architecture, BAA execution, PHI encryption at rest (AES-256) and in transit (TLS 1.3).
Telecom, Travel & Education CRM Multi-tenant data isolation, GDPR/PII masking, and role-based operational access boundaries.
Call Center CRM Encrypted telephony streams, voice recording PII redacting, and secure CTI protocol integration.

Enterprise Integrations

8 Integrations
Integration Services Integration Security & Transport Standards
Open Dental to GoHighLevel HIPAA-compliant middleware sync pipelines, end-to-end encryption, and automated sensitive dental data safeguards.
Dentrix to GoHighLevel Secure encrypted sync bridge, access audits, zero local caching of unencrypted PHI, and token authentication.
Salesforce Integrations Certified REST/SOAP API connectors, mutual TLS, scoped access permissions, and automated webhook retries.
WhatsApp & Telephony Integrations End-to-end encrypted messaging channels, webhook signature verification, and carrier API security.
Outlook, MindBody & Zillow Integrations Enterprise OAuth 2.0 authorization, minimal data scope grants, and encrypted cloud synchronization.

Cloud & DevOps

10 Core Practices
Environment & Tooling Infrastructure Security & Reliability Role
AWS, Azure & DigitalOcean VPC network segregation, private subnets, security groups, and automated encrypted backups across regions.
Kubernetes & Docker Container image vulnerability scanning, least-privilege service accounts, and automated pod health checks.
DevOps & AIOps Secure CI/CD pipelines, automated SAST/dependency scanning, Software Bill of Materials (SBOM), and alerts.
Cloud Migration & SRE Zero-data-loss migration playbooks, high-availability architecture, and targeted RTO 4h / RPO 1h resilience.
LLM Observability Continuous model telemetry, prompt injection detection, token usage auditing, and response quality monitoring.
To subscribe to real-time subprocessor modification announcements and security updates, email our compliance desk at info@varianceinfotech.com.

Frequently Asked Questions

Answers to common enterprise security, compliance, data handling, and procurement questions.

Yes. Yes. Security is incorporated into application development, cloud infrastructure, data handling, access management, monitoring, incident response, and AI governance practices.

Yes. The Trust Center states that data at rest is protected using AES-256 encryption and data in transit using TLS 1.2 or TLS 1.3..

No. The Trust Center states that customer code, database assets, voice recordings, transcripts, and proprietary client documents are not used to train or fine-tune public foundation AI models.

For healthcare, dental, and telehealth engagements involving PHI, the Trust Center states that Variance Infotech implements HIPAA-compliant security architectures and supports formal BAAs.

The Trust Center identifies SOC 2 Type II as an attestation and provides a process for requesting the report.

Yes. Security and compliance documentation can be requested through the Trust Center and security team. Certain sensitive documents are provided under NDA.

Yes. The Trust Center states that the compliance team supports SIG, CAIQ, VSA, and customized internal procurement security assessments.

Yes.Yes. The Trust Center states that customers can request complete deletion of their data, including upon contract termination, subject to the applicable contractual process.

Variance Infotech maintains a documented incident-response framework covering detection, containment, eradication, recovery, and post-mortem activities.

Visit the Variance Infotech Trust Center for the detailed security controls, documentation, subprocessors, FAQs, and compliance information.

We use cookies to provide better experience on our website. By continuing to use our site, you accept our Cookies and Privacy Policy.

Accept