One page for whatever your legal, IT, or security team asks first: NDAs, MSAs, security questionnaires, data residency, and DPAs. Including the honest answer to the question procurement teams eventually ask directly: no, we're not SOC 2 certified, and here's exactly why that's the right framework for a services partner, not the wrong one to be missing.
Complete discretion under NDA is standard, not an add-on. We're comfortable working through your own NDA template rather than insisting on ours.
We don't add new end-client names to our own marketing without explicit approval. White-label discretion runs both directions.
We work under a Master Service Agreement with individual statements of work per project, and we're comfortable with standard enterprise legal review timelines.
Handled alongside your IT and security teams as a normal part of the engagement, not treated as a delay to negotiate around.
Data handling documented against your requirements, with a Data Processing Agreement in place before any user record moves.
Single sign-on and identity provider integrations configured and tested against your IT team's actual requirements, including for AMS-LMS identity federation.
Different content, permissions, and reporting per department scoped from day one, not bolted on after a pilot outgrows its structure.
Most enterprise clients keep us on past launch as platforms, departments, and compliance requirements change, rather than re-scoping a new vendor each time.
VertoLaunch is a professional services and delivery partner, not a SaaS platform, so we're not SOC 2 certified, and we won't pretend otherwise or bury the answer. SOC 2 evaluates a software vendor's own infrastructure and controls; the systems that actually hold your learner data are the LMS platforms you choose and control, Docebo, LearnWorlds, Cornerstone, Workday Learning, or others, and their own security posture and certifications are what apply there. Our part of the engagement is supporting your team through security questionnaires and vendor risk review, documenting data handling with a DPA, and configuring SSO and identity integration to your requirements, real accountability without a certification claim we haven't earned. Your data and content stay yours; the underlying platform stays licensed from its own vendor. We build, configure, and manage it on your behalf and don't claim ownership or infrastructure custodianship beyond the scope of the engagement.
Evaluating us for an enterprise, association, or fund-level engagement? See our LMS implementation & migration service for how this plays out on a real project, or our AMS-LMS integration guide if identity federation and credit writeback are the specific concern.
Book a 20-minute call and bring your security questionnaire or procurement checklist. We'll tell you honestly what we can and can't check off.
Book Your 20-Min Discovery Call →