Skip to main content

Trust Center

Security and privacy at Vantage Fit

Everything your security and compliance team needs to review Vantage Fit before a demo. Certifications, data hosting, what we collect, who can see it, and how to request documentation.

Vantage Fit is ISO 27001 and ISO 27701 certified, and SOC 2, GDPR and HIPAA compliant, with a Business Associate Agreement (BAA) covering the lab report pipeline.

Download the ISO certificates below, or email our security team at security@vantagecircle.com for the SOC 2 Type II report, DPA, and BAA.

Since 2015 we have built one product, continuously, and we are still independent.

No acquisition, no rebrand, no forced migration for our customers.

  1. Data hosting

    Hosted in the region you choose

    Regional hosting is standard, not an enterprise add-on.

  2. Access model

    Employees see their own data. HR sees aggregate trends.

    Individual health data stays private. HR dashboards report aggregated participation, health patterns, and engagement levels.

  3. Data sharing

    We do not share employee PII with third parties

    Personally identifiable information stays inside the Vantage Fit ecosystem, never shared.

  4. What we collect

    The health data employees choose to share

    A health-risk questionnaire, an optional profile, uploaded lab reports, mood check-ins, and activity synced from Apple Health, Fitbit or Garmin. All of it is optional. Onboarding and the assessment can be skipped, and Lite Mode collects none of it.

  5. Roles

    You run the program; we store and process the data for you

    Your organization picks the hosting region and decides how the program runs. Vantage Fit stores and processes employee data on your behalf, within that region, under a signed Business Associate Agreement (BAA) covering lab-report data.

  6. Consent

    Sharing health data is voluntary

    Employees choose what to share. The health assessment, profile, and lab-report uploads are opt-in and can be skipped. Wearable connections use each provider's own consent screen.

  7. Deletion

    Employees can delete their data; leavers lose access

    An employee can permanently delete their own lab reports. On account deletion the name and email are hashed and sign-in is cleared, while aggregate historical activity is retained for reporting. When someone leaves, their account is deactivated so they can no longer sign in.

  8. AI and processing

    AI reads lab text and writes aggregate summaries, nothing else

    AI is used in exactly two places: reading the values off an uploaded lab report, and writing group-level summaries from aggregated signals with no personal identifiers attached. No model profiles an individual for HR.

  9. Privacy stance

    Employee privacy comes before HR data appetite

    Vantage Fit is a habit product, not a clinical or surveillance tool. We measure success by whether employees open the app, and employees only keep opening an app they trust.

  10. Documentation

    Most security reviews need paperwork, not promises

    Download our ISO 27001 and ISO 27701 certificates below. For SOC 2 Type II, our DPA, BAA, and VAPT report, email our InfoSec team at security@vantagecircle.com.

Documentation

Certifications and documentation

Our ISO certificates are available to download below. SOC 2 Type II, our DPA, BAA, and VAPT report contain sensitive detail and are shared with your security team on request.

Available on request

  • SOC 2 Type II report
  • Data Processing Agreement (DPA)
  • Business Associate Agreement (BAA)
  • VAPT / penetration-test report
Email our InfoSec team
From the first call, the team was extremely transparent, collaborative and considerate of all our corporate requirements.
Teva Pharmaceuticals, email testimonial

Reviewed and trusted by

  1. Teva Pharmaceuticals
  2. Serum Institute of India
  3. Dudley Building Society
  4. Momentum Investments

Send us your security review checklist

Our team answers security and compliance questionnaires directly.

Book a demo