Security Policy

Effective Date: August 7, 2026
Last Updated: August 7, 2026

At VRiseIn, LLC (“VRiseIn,” “we,” “us,” or “our”), security is a fundamental part of how we design, develop, deliver, and support technology solutions.

As a Texas-based technology and IT services company, we understand that our customers rely on us to protect their systems, applications, infrastructure, and information. Our security approach is designed to help organizations reduce risk, protect critical assets, maintain operational resilience, and build trust in their digital environments.

This Security Policy describes the principles and practices that guide VRiseIn’s approach to information security across our technology services, internal operations, development environments, infrastructure, and customer engagements.

1. Our Security Commitment

Security is not an afterthought at VRiseIn.

We work to incorporate security considerations throughout the technology lifecycle, from initial strategy and architecture through development, deployment, monitoring, maintenance, and retirement.

Our security objectives include:

  • Protecting information and technology assets
  • Maintaining confidentiality of sensitive information
  • Supporting data integrity and accuracy
  • Promoting system availability and resilience
  • Reducing cybersecurity risk
  • Supporting secure software development
  • Protecting customer environments
  • Identifying and responding to security incidents
  • Promoting responsible technology practices
  • Continuously improving our security capabilities

2. Security by Design

We believe security should be incorporated into technology solutions from the beginning rather than added after development is complete.

Depending on the project and applicable requirements, security considerations may be incorporated into:

  • Business and technical requirements
  • System architecture
  • Application design
  • Database design
  • API development
  • Cloud infrastructure
  • Identity management
  • Authentication
  • Authorization
  • Data protection
  • Software development
  • Testing
  • Deployment
  • Monitoring
  • Maintenance

Security requirements may vary depending on the customer’s industry, regulatory obligations, technology environment, and project scope.

3. Information Security Principles

Our security approach is based on three fundamental principles.

Confidentiality

We work to prevent unauthorized access or disclosure of information.

Integrity

We work to protect information and systems from unauthorized modification or destruction.

Availability

We work to support reliable access to systems and information when required.

These principles help guide our technology architecture, operational processes, and security practices.

4. Access Control

VRiseIn applies access-control principles designed to limit access to systems and information based on legitimate business and operational requirements.

Where appropriate, security controls may include:

  • Role-based access
  • Least-privilege principles
  • Authentication controls
  • Multi-factor authentication
  • Administrative access restrictions
  • User account management
  • Access reviews
  • Credential management
  • Session controls

Access to customer information and systems is intended to be limited to authorized personnel who require access to perform their responsibilities.

5. Authentication & Identity Security

Depending on the technology environment, VRiseIn may implement security mechanisms such as:

  • Multi-factor authentication (MFA)
  • Strong password policies
  • Single sign-on (SSO)
  • Role-based access control (RBAC)
  • Identity and access management (IAM)
  • Privileged access management
  • Secure authentication protocols
  • Session management

Customers are also responsible for maintaining appropriate authentication and access controls within systems they own or control.

6. Data Protection

We take reasonable measures designed to protect information against unauthorized access, disclosure, alteration, loss, or destruction.

Depending on the Service and technical environment, security measures may include:

  • Encryption in transit
  • Encryption at rest where appropriate
  • Secure authentication
  • Access controls
  • Network security
  • Backup mechanisms
  • Logging and monitoring
  • Secure data handling procedures

The specific security controls applicable to a customer environment may be defined by the relevant service agreement, Statement of Work, security requirements, or data processing agreement.

7. Secure Software Development

For software development projects, VRiseIn promotes secure development practices throughout the Software Development Lifecycle (SDLC).

Depending on project requirements, practices may include:

  • Secure architecture
  • Secure coding standards
  • Code review
  • Dependency management
  • Vulnerability assessment
  • Security testing
  • Authentication and authorization controls
  • Input validation
  • API security
  • Secrets management
  • Logging
  • Error handling
  • Security monitoring
  • Secure deployment practices

Security requirements may be incorporated into development planning, testing, deployment, and maintenance activities.

8. Application Security

We design applications with security considerations appropriate to their intended use and risk profile.

Application security measures may include:

  • Secure authentication
  • Authorization controls
  • Input validation
  • API protection
  • Encryption
  • Secure session management
  • Rate limiting
  • Security logging
  • Vulnerability management
  • Secure configuration
  • Dependency monitoring

For high-risk applications, additional security assessments or testing may be performed when included in the project scope.

9. Cloud Security

VRiseIn may design, implement, or manage cloud environments using platforms such as:

  • Amazon Web Services (AWS)
  • Microsoft Azure
  • Google Cloud Platform
  • Private Cloud
  • Hybrid Cloud
  • Multi-Cloud Environments

Cloud security practices may include:

  • Identity and access management
  • Network segmentation
  • Encryption
  • Secure configuration
  • Logging
  • Monitoring
  • Backup strategies
  • Infrastructure security
  • Security groups and firewall controls
  • Vulnerability management
  • Infrastructure-as-Code security

Cloud environments operate under a shared-responsibility model. Customers remain responsible for security responsibilities assigned to them by the applicable cloud provider and service agreement.

10. Network Security

Depending on the environment, VRiseIn may implement network security controls such as:

  • Firewalls
  • Network segmentation
  • Secure VPN connectivity
  • Intrusion detection and prevention
  • Traffic monitoring
  • Access controls
  • Secure remote access
  • Network configuration management

Network security architecture is designed according to the specific business and technical requirements of each environment.

11. Endpoint Security

Where included within our managed IT or security services, endpoint security may include controls designed to protect:

  • Workstations
  • Laptops
  • Servers
  • Mobile devices
  • Network devices
  • Virtual machines

Security controls may include endpoint protection, patch management, access controls, monitoring, and configuration management.

12. Vulnerability Management

VRiseIn may perform or recommend vulnerability assessments as part of applicable security engagements.

Depending on the agreed scope, vulnerability management may include:

  1. Identifying potential vulnerabilities
  2. Assessing security risks
  3. Prioritizing vulnerabilities
  4. Recommending remediation
  5. Implementing security improvements
  6. Validating remediation where applicable

Customers remain responsible for approving and implementing remediation actions unless VRiseIn has been specifically contracted to perform them.

13. Penetration Testing

Where specifically authorized and included within a project scope, VRiseIn may provide or coordinate penetration testing and security assessments.

Security testing must be performed only against systems for which the customer has appropriate authorization.

Testing may evaluate areas such as:

  • Web applications
  • APIs
  • Network infrastructure
  • Cloud environments
  • Mobile applications
  • Authentication systems
  • Configuration security

Testing scope, methodology, timing, reporting, and remediation requirements should be defined in a separate agreement or Rules of Engagement.

14. Security Monitoring

Where included in a customer’s Service, VRiseIn may use monitoring technologies to identify unusual activity, operational issues, or potential security events.

Monitoring capabilities may include:

  • Security logs
  • System logs
  • Application logs
  • Network events
  • Authentication events
  • Endpoint activity
  • Infrastructure monitoring
  • Security alerts

The availability and scope of monitoring depend on the customer’s service plan, technical environment, and applicable agreement.

15. Incident Response

VRiseIn maintains processes for identifying, assessing, responding to, and recovering from security incidents affecting systems under our responsibility.

Potential security incidents may include:

  • Unauthorized access
  • Malware
  • Ransomware
  • Data exposure
  • Credential compromise
  • Phishing
  • Denial-of-service activity
  • System compromise
  • Suspicious activity
  • Security vulnerabilities

Our response may include:

  1. Detection
  2. Initial assessment
  3. Containment
  4. Investigation
  5. Remediation
  6. Recovery
  7. Documentation
  8. Post-incident review

Where required by applicable law or contractual obligations, we will provide appropriate notifications regarding qualifying security incidents.

16. Customer Security Responsibilities

Security is a shared responsibility between VRiseIn and our customers.

Customers are responsible for maintaining appropriate security practices within systems, applications, accounts, devices, and infrastructure under their control.

Customers should:

  • Use strong passwords
  • Enable MFA where available
  • Restrict user permissions
  • Keep software updated
  • Maintain appropriate backups
  • Protect API keys and credentials
  • Train employees on cybersecurity
  • Avoid sharing passwords
  • Review user access regularly
  • Report suspicious activity promptly
  • Maintain appropriate business continuity procedures

Where a customer’s actions or configuration affect security, VRiseIn cannot guarantee protection against resulting security incidents.

17. Security Awareness

VRiseIn promotes security awareness among personnel who have responsibilities involving company systems, customer environments, or sensitive information.

Security awareness may include education relating to:

  • Phishing
  • Password security
  • Social engineering
  • Data protection
  • Access management
  • Secure handling of information
  • Device security
  • Incident reporting
  • Responsible technology use

18. Employee & Contractor Access

Access to systems and information is intended to be granted according to job responsibilities and business requirements.

Where appropriate, personnel access may be:

  • Authorized
  • Limited
  • Monitored
  • Reviewed
  • Modified when responsibilities change
  • Revoked when access is no longer required

Contractors and third-party personnel may be subject to applicable contractual and security requirements.

19. Third-Party Security

VRiseIn may rely on third-party technology providers for services such as:

  • Cloud infrastructure
  • Hosting
  • Email
  • Security monitoring
  • Payment processing
  • Software development
  • Analytics
  • Customer support
  • Data storage
  • Communications

We seek to work with reputable technology providers appropriate to the services being delivered.

Third-party providers maintain their own security policies and controls, and their security responsibilities may be governed by their respective agreements.

20. Data Privacy

Security and privacy are closely connected.

VRiseIn’s collection and processing of personal information is described in our Privacy Policy.

Depending on the customer, service, industry, and applicable regulations, additional contractual privacy and security requirements may apply.

21. Regulatory & Industry Requirements

VRiseIn recognizes that organizations may operate under different regulatory and industry requirements.

Depending on the customer’s needs, our technology solutions may be designed to support requirements or security objectives associated with frameworks and regulations such as:

  • HIPAA
  • PCI DSS
  • GDPR
  • SOC 2
  • NIST
  • ISO/IEC 27001
  • CCPA/CPRA
  • Applicable U.S. state privacy laws
  • Industry-specific security requirements

Compliance depends on the complete technology environment, organizational policies, processes, personnel, vendors, and controls.

VRiseIn does not represent that a particular Service alone guarantees regulatory compliance unless expressly stated in a written agreement.

22. Healthcare Information

VRiseIn may provide technology solutions to healthcare organizations.

Where applicable, healthcare projects may incorporate security and privacy requirements relating to protected health information.

Specific healthcare security obligations may be established through appropriate agreements, including a Business Associate Agreement where legally required.

Customers should not submit protected health information through general website forms unless specifically instructed to use an approved secure channel.

23. Financial & Payment Information

VRiseIn may provide technology services to financial institutions and businesses handling financial information.

Customers remain responsible for implementing appropriate security controls within systems they operate.

Where payment processing is handled by third-party payment providers, payment information may be processed according to the provider’s security and privacy practices.

24. Artificial Intelligence Security

VRiseIn develops and implements AI-powered technologies with security and responsible-use considerations.

Depending on the AI solution, security measures may include:

  • Access controls
  • Data isolation
  • Secure APIs
  • Authentication
  • Encryption
  • Logging
  • Monitoring
  • Prompt and input controls
  • Model access restrictions

Customers should not submit confidential, regulated, or sensitive information to AI systems unless the applicable service specifically supports such processing.

AI outputs should be reviewed appropriately before being used for sensitive or consequential decisions.

25. IoT & Connected Device Security

For Internet of Things (IoT), sensor, monitoring, and connected-device solutions, security may include:

  • Device authentication
  • Secure communications
  • API security
  • Access controls
  • Device management
  • Data encryption
  • Monitoring
  • Secure configuration

The specific security architecture depends on the device, connectivity method, deployment environment, and project requirements.

26. Business Continuity & Disaster Recovery

Where included within a Service, VRiseIn may help organizations develop:

  • Backup strategies
  • Disaster recovery plans
  • Business continuity strategies
  • Recovery procedures
  • Redundancy
  • High-availability architectures
  • Cloud recovery environments

No backup or disaster recovery strategy can eliminate every possible risk.

Customers should maintain business continuity plans appropriate to their operational requirements.

27. Security Incident Reporting

If you believe you have identified a security vulnerability, unauthorized access, or security incident involving a VRiseIn system or Service, please contact us promptly.

Security Contact:
info@vrisein.com

Please include “Security Issue” or “Security Incident” in the subject line.

When reporting a potential security issue, please provide enough information for our team to understand and investigate the issue.

Please do not publicly disclose a suspected vulnerability before giving us a reasonable opportunity to investigate and address it.

28. Responsible Disclosure

We encourage responsible reporting of security vulnerabilities.

If you identify a potential vulnerability in a VRiseIn website, application, or Service:

  1. Report the issue privately.
  2. Provide relevant technical details.
  3. Avoid accessing or modifying information that does not belong to you.
  4. Avoid disrupting systems or services.
  5. Do not publicly disclose the vulnerability while it is being investigated.
  6. Allow reasonable time for assessment and remediation.

VRiseIn may acknowledge security researchers who responsibly report vulnerabilities, subject to our discretion and applicable circumstances.

29. Security Limitations

While VRiseIn implements reasonable security practices, no technology environment can be guaranteed to be completely secure.

Cybersecurity risks continually evolve, and new vulnerabilities and attack methods may emerge.

Accordingly, VRiseIn does not guarantee that:

  • Every security threat will be detected
  • Every vulnerability will be prevented
  • Every cyberattack will be stopped
  • Services will always be uninterrupted
  • Data will never be exposed
  • Systems will never experience security incidents

Our objective is to continuously identify, reduce, monitor, and manage technology risks.

30. Security Improvements

Security is an ongoing process.

VRiseIn continuously evaluates opportunities to improve:

  • Technology architecture
  • Security practices
  • Development processes
  • Monitoring capabilities
  • Access controls
  • Infrastructure security
  • Incident response
  • Employee awareness
  • Vendor management
  • Risk management

As technology and cybersecurity threats evolve, our security practices may also evolve.

31. Changes to This Security Policy

VRiseIn may update this Security Policy periodically to reflect:

  • Changes in technology
  • New security practices
  • Changes to our Services
  • Regulatory developments
  • Changes to our infrastructure
  • Improvements to security processes

The latest version will be published on this page with the updated effective date.

32. Contact VRiseIn

For questions regarding this Security Policy or our security practices, contact us.

VRiseIn, LLC

Head Office:
Sugar Land, Texas 77498
United States

Security & General Inquiries:
info@vrisein.com

Website:
www.vrisein.com

For security incidents or vulnerabilities, please include “Security Issue” in the email subject line.

33. Related Policies

For additional information, please review:

Our Commitment to Security

At VRiseIn, security is fundamental to responsible technology innovation.

We strive to build and deliver technology solutions that are secure, resilient, scalable, and designed with the evolving cybersecurity landscape in mind.

VRiseIn, LLC
Technology • Innovation • Digital Transformation

Sugar Land, Texas, USA

info@vrisein.com
www.vrisein.com

new service

Register Your Domain Today!

Find the perfect domain name for your business, brand, or idea. Secure it now before someone else does!

Power your presence online with the perfect domain.