Trust Center

Security & compliance

Domain: virtuous.work. Controls modeled after GRC programs (e.g. Vanta) for SOC 2, ISO/IEC 27001, and HIPAA readiness.

Not a certificate or BAA. This page is a live control map. Official SOC 2, ISO 27001, or HIPAA attestation requires legal analysis, BAAs where needed, risk analysis, and often an independent auditor.

Also see

  • Privacy Policy (includes health data / PHI notes)
  • Terms of Use
  • Credentials vault, install app, and Earn are available after sign-in (Earn is Tier 1 only).