Security posture

Answers before the questionnaire.

A visitor management system holds identity documents, site access rules and a record of who was where. Here is how Visit+ is built, stated plainly enough that your security team can check it.

Foundations

Where it runs, and who it trusts.

Hosted on Microsoft AzureRunning on Microsoft's certified cloud infrastructure, in the region you require.
Microsoft Entra IDEvery visitor and employee identity is issued and authenticated through Entra — not a password table we invented.
Claims-based sessionsEvery authenticated action carries its own claims, scoped to role and site.
Immutable audit trailVisits, signatures and permission changes are recorded to be read back years later.

Identity

We did not invent our own identity system.

Every visitor and employee identity in Visit+ is issued and authenticated through Microsoft Entra ID. That is a deliberate constraint: identity is the part of this system with the worst failure mode, so it belongs with the provider your organization already audits.

  • Hosts and administrators sign in with their existing organizational identity
  • Visitor identities are issued through Entra rather than stored as local credentials
  • Your tenant's conditional access, MFA and lifecycle policies apply — we do not work around them
  • Sessions are claims-based; every authenticated action carries its own scope

Access control

Nobody sees more than their job needs.

Roles and users are scoped to a company and to sites within it. A host at one site cannot browse another site's visitors; a security user sees the operational picture without inheriting administration.

Company scopingMultiple companies live under one account without sharing data. Users switch companies without switching logins.
Site scopingFlows, kiosks, employees and visits belong to a site. Permissions follow that boundary.
Role definitionsRoles are configurable rather than a fixed three-tier ladder, so they can match how your organization is actually structured.

Being straight with you

What we don't claim.

Vendors routinely present their cloud provider's certifications as their own. We won't do that to you, because your auditor will catch it.

Azure's certifications are Microsoft'sVisit+ runs on Microsoft Azure, and Azure holds a long list of attestations. Those cover Microsoft's infrastructure — they are not a Visit+ certification, and we will not present them as one.
Ask us where we areIf your procurement process requires a specific attestation, raise it early. We will tell you exactly what we hold today, what is underway and what we would commit to for your deployment.

Security review

Send us the questionnaire.

We'd rather answer it directly than have you infer the answers from a marketing page. Bring your security team to the demo.