An AI Roleplay Platform Built for Organizations Where Security Is Non-Negotiable
Virtual Sapiens is built with privacy-first, consent-driven architecture from the ground up. Enterprise-grade security, full regulatory compliance, and data controls that give your organization and your clients confidence at every stage of deployment.
Certified. Compliant. Built for Enterprise.
SOC 2 Type II
Independently audited and verified. Annual control self-assessments and penetration testing ensure ongoing compliance.
GDPR Compliant
Clear data retention policies, user consent controls, and configurable data handling practices for organizations operating in the EU and beyond.
European AI Act Alignment
Behavioral observation language rather than emotional inference, clear user controls over data and processing.
SOC 2 System Description Available
Contact our team to request documentation
How We Handle Your Data
Video Processing Without Storage
Videos can be processed entirely on the client’s device. Your video never leaves your device unless you choose to save it. This is how the platform is built.
PII Encryption in Transcripts
Personally identifiable information in transcripts can be encrypted.
Data Retention You Control
Organizations configure their own data retention policies. Customer data is purged in accordance with those policies when clients leave the
Feedback Framed as Behavioral Observation
Virtual Sapiens uses behavioral observation language rather than emotional inference. The platform reports on vocal tone, not emotional state. This is a deliberate product decision that has directly resolved compliance concerns for enterprise clients during procurement.
Built to Meet Enterprise Security Standards at Every Level
Virtual Sapiens maintains rigorous security controls across every layer of the platform.
01 Access and encryption
Access to production systems, databases, networks, and applications is restricted to authorized users with documented business needs. Multi-factor authentication is required for all remote access. Data is encrypted at rest and in transit. The production network is segmented to prevent unauthorized access to customer data.
02 Monitoring and testing
Infrastructure performance is monitored continuously with automated alerting for predefined thresholds and a log management system that tracks events with potential security impact. Penetration testing is conducted at least annually and remediation is completed within defined SLAs. Firewalls are reviewed and updated on a defined annual cycle.
03 People and vendors
All employees and contractors sign confidentiality agreements and acknowledge a code of conduct at the time of hire or engagement. A formal vendor management program governs third-party relationships, with critical vendors reviewed annually.
04 Continuity and response
Business Continuity and Disaster Recovery plans are documented and tested at least annually. Incident response policies are in place, tested regularly, and communicated to authorized users. Virtual Sapiens maintains cybersecurity insurance to mitigate the financial impact of business disruptions.
No client data is ever used to train Virtual Sapiens AI models. Data remains anonymous and is processed in accordance with the platform’s privacy-first architecture.
For Your Security and IT Team
Our team is available to support your IT and legal reviewers with the materials they need to move through procurement efficiently. Available upon request: SOC 2 Type II report, system description, data processing agreements, security questionnaire responses, and compliance documentation for GDPR and European AI Act alignment.
Frequently Asked Questions
Yes. Virtual Sapiens is SOC 2 Type II certified, independently audited and verified. Compliance is maintained through annual control self-assessments and penetration testing. The SOC 2 report and system description are available on request for procurement reviews.
Yes. Virtual Sapiens is GDPR compliant, with clear data retention policies, user consent controls, and configurable data handling practices for organizations operating in the EU and beyond. Data processing agreements are available on request.
Videos can be processed entirely on the learner's device, without ever being stored. Video never leaves the device unless the user chooses to save it. This is how the platform is built, not an optional setting bolted on afterward.
Yes. Personally identifiable information in transcripts can be encrypted, and organizations control the data policies that govern how transcript data is handled and retained.
- No. Client data is never used to train Virtual Sapiens AI models. Data remains anonymous and is processed in accordance with the platform's privacy-first architecture.
Available on request: the SOC 2 Type II report, system description, data processing agreements, security questionnaire responses, and compliance documentation for GDPR and European AI Act alignment. Our team works directly with IT and legal reviewers to keep procurement moving.
Organizations set their own data retention policies, and customer data is purged in accordance with those policies when a client leaves the service. Your data, your rules, from onboarding through offboarding.
Virtual Sapiens uses behavioral observation language, not emotional inference. The platform reports on what it can observe, vocal tone rather than emotional state, posture rather than mood. This matters because how feedback is framed carries real compliance weight: it aligns with the European AI Act's treatment of emotion inference and has directly resolved procurement concerns for enterprise clients.