Security posture
Answers before the questionnaire.
A visitor management system holds identity documents, site access rules and a record of who was where. Here is how Visit+ is built, stated plainly enough that your security team can check it.
Foundations
Where it runs, and who it trusts.
Identity
We did not invent our own identity system.
Every visitor and employee identity in Visit+ is issued and authenticated through Microsoft Entra ID. That is a deliberate constraint: identity is the part of this system with the worst failure mode, so it belongs with the provider your organization already audits.
- Hosts and administrators sign in with their existing organizational identity
- Visitor identities are issued through Entra rather than stored as local credentials
- Your tenant's conditional access, MFA and lifecycle policies apply — we do not work around them
- Sessions are claims-based; every authenticated action carries its own scope
Access control
Nobody sees more than their job needs.
Roles and users are scoped to a company and to sites within it. A host at one site cannot browse another site's visitors; a security user sees the operational picture without inheriting administration.
Being straight with you
What we don't claim.
Vendors routinely present their cloud provider's certifications as their own. We won't do that to you, because your auditor will catch it.
Security review
Send us the questionnaire.
We'd rather answer it directly than have you infer the answers from a marketing page. Bring your security team to the demo.