An AI Roleplay Platform Built for Organizations Where Security Is Non-Negotiable

Virtual Sapiens is built with privacy-first, consent-driven architecture from the ground up. Enterprise-grade security, full regulatory compliance, and data controls that give your organization and your clients confidence at every stage of deployment.

SOC 2 Type IIGDPREuropean AI Act Alignment

The Virtual Sapiens roleplay set-up, on step 2 of 5, Devices. A camera preview shows a person at a desk, and beneath it the line: Your video is 100% private and will not be viewed, transmitted, or stored unless you opt-in.

Certified. Compliant. Built for Enterprise.

SOC 2 Type II​

Independently audited and verified. Annual control self-assessments and penetration testing ensure ongoing compliance.

GDPR Compliant

Clear data retention policies, user consent controls, and configurable data handling practices for organizations operating in the EU and beyond.

European AI Act Alignment

Behavioral observation language rather than emotional inference, clear user controls over data and processing.

SOC 2 System Description Available — Contact our team to request documentation. Visit the Trust Center

How We Handle Your Data

Video Processing Without Storage

Videos can be processed entirely on the client’s device. Your video never leaves your device unless you choose to save it. This is how the platform is built.

Data Retention You Control

Organizations configure their own data retention policies. Customer data is purged in accordance with those policies when clients leave the service.

PII Redaction in Transcripts

Personally identifiable information in transcripts can be redacted. If turned on, a local model redacts the transcript at the start of the AI pipeline, before it is sent to a third-party AI provider, so no PII is transmitted or analyzed for feedback. Redaction is configured at the cohort, team or organization level.

Feedback Framed as Behavioral Observation

Virtual Sapiens uses behavioral observation language rather than emotional inference. The platform reports on vocal tone, not emotional state. This is a deliberate product decision that has directly resolved compliance concerns for enterprise clients during procurement.

Virtual Sapiens organization settings. Under Data and Sharing, a toggle controls whether users can delete their own meetings and practice sessions, and Allow Saving Practice Recordings offers Required, Let User Choose or Not Allowed. Below, Data Retention sets a data termination period in days.

Built to Meet Enterprise Security Standards at Every Level

Virtual Sapiens maintains rigorous security controls across every layer of the platform.

Access and encryption

Access to production systems, databases, networks, and applications is restricted to authorized users with documented business needs. Multi-factor authentication is required for all remote access. Data is encrypted at rest and in transit. The production network is segmented to prevent unauthorized access to customer data.

Monitoring and testing

Infrastructure performance is monitored continuously with automated alerting for predefined thresholds and a log management system that tracks events with potential security impact. Penetration testing is conducted at least annually and remediation is completed within defined SLAs. Firewalls are reviewed and updated on a defined annual cycle.

People and vendors

All employees and contractors sign confidentiality agreements and acknowledge a code of conduct at the time of hire or engagement. A formal vendor management program governs third-party relationships, with critical vendors reviewed annually.

Continuity and response

Business Continuity and Disaster Recovery plans are documented and tested at least annually. Incident response policies are in place, tested regularly, and communicated to authorized users. Virtual Sapiens maintains cybersecurity insurance to mitigate the financial impact of business disruptions.

No client data is ever used to train Virtual Sapiens AI models.

Privacy-first architecture · Anonymous processing

View Full Security Documentation in the Trust Center

For Your Security and IT Team

Our team is available to support your IT and legal reviewers with the materials they need to move through procurement efficiently. Available upon request: SOC 2 Type II report, system description, data processing agreements, security questionnaire responses, and compliance documentation for GDPR and European AI Act alignment.

Frequently Asked Questions

Yes. Virtual Sapiens is SOC 2 Type II certified, independently audited and verified. Compliance is maintained through annual control self-assessments and penetration testing. The SOC 2 report and system description are available on request for procurement reviews.

Yes. Virtual Sapiens is GDPR compliant, with clear data retention policies, user consent controls, and configurable data handling practices for organizations operating in the EU and beyond. Data processing agreements are available on request.

Videos can be processed entirely on the learner's device, without ever being stored. Video never leaves the device unless the user chooses to save it. This is how the platform is built, not an optional setting bolted on afterward.

It can be. If turned on, a local model redacts personally identifiable information from the transcript at the start of the AI pipeline, so no PII is transmitted to or analyzed by a third-party AI provider. Redaction is configured at the cohort, team or organization level. Encryption is separate and always on: all data is encrypted in transit and at rest.

No. Client data is never used to train Virtual Sapiens AI models. Data remains anonymous and is processed in accordance with the platform's privacy-first architecture.

Available on request: the SOC 2 Type II report, system description, data processing agreements, security questionnaire responses, and compliance documentation for GDPR and European AI Act alignment. Our team works directly with IT and legal reviewers to keep procurement moving.

Organizations set their own data retention policies, and customer data is purged in accordance with those policies when a client leaves the service. Your data, your rules, from onboarding through offboarding.

Virtual Sapiens uses behavioral observation language, not emotional inference. The platform reports on what it can observe, vocal tone rather than emotional state, posture rather than mood. This matters because how feedback is framed carries real compliance weight: it aligns with the European AI Act's treatment of emotion inference and has directly resolved procurement concerns for enterprise clients.

Ready to Scale Your Programs?

See how Virtual Sapiens can extend your programs with scalable practice, continuous engagement, and measurable behavioral insights.