Visiontech Consulting is actively advancing its compliance and security-readiness program with Drata, with a focus on preparing for an upcoming SOC 2 examination and aligning with the NIST 2.0 Cybersecurity Framework. This work supports Visiontech's commitment to governance, access control, secure development, risk management, incident response, vendor oversight, evidence collection, and ongoing control monitoring.
Actively preparing for an upcoming examination of our system based on the criteria set forth in DC 200, the 2018 Description Criteria for a Description of a Service Organization's System in a SOC 2 Report.
Aligning internal security practices with the NIST 2.0 Cybersecurity Framework to support stronger governance, asset awareness, protection, detection, response, and recovery capabilities.
Working toward certification readiness under the Canadian Program for Cyber Security Certification, the federal program that verifies cyber security controls for suppliers to Canada’s defence and public sector procurements.
Using Drata’s compliance automation software to prepare for NIST 2.0 and the upcoming SOC 2 examination, with continuous monitoring of our compliance posture to follow post-audit.
Drata is a security and compliance automation platform that continuously monitors and collects evidence of a company’s security controls and streamlines audit-readiness workflows.
drata.comStatus note. SOC 2, NIST CSF 2.0, and CPCSC are all work in progress. Visiontech is not currently representing that it has completed a SOC 2 audit, NIST CSF 2.0 alignment, or CPCSC certification unless and until a formal report or certification is issued. Compliance-readiness documentation, including the Drata Letter of Assertion, may be made available to qualified customers and partners upon request.
Defined ownership, policies, and oversight for security decisions.
Least privilege access and role-based permissions across systems.
Ongoing identification, assessment, and treatment of security risks.
Security considerations built into design, development, and release.
Review and monitoring of the partners and services we rely on.
Defined procedures for detecting, escalating, and resolving incidents.
Drata-supported evidence collection and continuous control monitoring.
Responsible handling of identity, video, and operational data.
Human oversight and appropriate use-case design for AI systems.
SOC 2 is a widely recognized framework for evaluating controls related to security, availability, processing integrity, confidentiality, and privacy. Visiontech is actively preparing for an upcoming SOC 2 examination. When a formal SOC 2 report becomes available, Visiontech may share it with qualified customers, partners, and procurement teams under appropriate confidentiality terms.
The NIST 2.0 Cybersecurity Framework provides a structured approach for managing cybersecurity risk. Visiontech is aligning its internal security practices with this framework to support stronger governance, asset awareness, protection, detection, response, and recovery capabilities.
The Canadian Program for Cyber Security Certification is the federal program that verifies the cyber security controls of suppliers to Canada’s defence and public sector procurements. Visiontech is working toward certification readiness so FACES2 can continue to serve defence and public sector programs as CPCSC requirements phase into federal contracts.
Disclaimer. SOC 2, NIST CSF 2.0, and CPCSC are active readiness projects at Visiontech. Work under each framework is in progress and compliance is not yet complete. No certification, attestation, or formal report is represented until it has been formally issued.
The FACES2 ecosystem is designed to support organizations that require stronger control over identity, access, monitoring, and response workflows. Across access control, identity authentication, AI video intelligence, and active incident management, FACES2 emphasizes secure system design, role-based access, operational oversight, and privacy-aware deployment practices.
FACES2 ID Authentication is designed to support organizations operating in regulated and identity-sensitive environments. The platform is developed with awareness of identity verification, biometric performance, financial-services, and digital trust requirements across multiple jurisdictions. The references below are relevant frameworks, standards, and regulatory considerations, not blanket certification claims.
Canadian digital trust and identity ecosystem guidance that informs our identity verification workflows.
Engagement with Canada's digital identity and trust community.
Reference standard for biometric performance testing and reporting.
European regulation for electronic identification and trust services, relevant to cross-border identity workflows.
Canadian financial transaction and identity verification requirements. FACES2 ID supports related verification workflows.
U.S. customer due diligence requirements for financial institutions, relevant to onboarding and KYC workflows.
Assurance concepts for identity proofing and authentication strength.
Supports verification workflows for government-issued IDs from 213+ countries and regions.
Visiontech designs its products with awareness of the sensitivity of identity, access, video, and operational security data. Our approach emphasizes controlled access, role-based permissions, privacy-aware workflows, and responsible handling of customer information.
Visiontech recognizes that AI, biometrics, and computer vision systems must be deployed responsibly. FACES2 solutions are designed to support human oversight, operational review, appropriate use-case configuration, and security-conscious deployment practices.
Qualified customers, partners, and procurement teams may request current compliance-readiness documentation, security questionnaires, the Drata Letter of Assertion, or supporting materials from Visiontech.
The Drata Letter of Assertion is available upon request. It describes compliance-readiness activities and is not a certification, audit opinion, attestation report, or SOC 2 report. Statements on this page describe readiness activities and design intent, not completed certifications or audits.