generated: '2026-07-21' method: searched source: https://viktor.com/security note: >- Viktor is an AI-employee product (Slack / Microsoft Teams) with no public, formally-specified developer API. These entries capture the security and privacy compliance posture the vendor publishes on its Security page rather than API-protocol conformance (OpenAPI/OAuth/etc.), which is not applicable here. standards: - id: soc2-type1 conforms: true evidence: Security page states SOC 2 Type 1 compliant (Type 2 in progress) - id: soc2-type2 conforms: false evidence: SOC 2 Type 2 reported as in progress - id: iso-27001 conforms: true evidence: Security page lists ISO 27001 - id: gdpr conforms: true evidence: Security page lists GDPR - id: ccpa conforms: true evidence: Security page title lists CCPA - id: casa-tier-3 conforms: true evidence: Security page title lists CASA Tier 3 (Google App Defense Alliance) - id: encryption-at-rest-in-transit conforms: true evidence: Security page describes encryption and workspace-isolated data architecture; credentials stored in encrypted vaults