Security and compliance: GDPR, HIPAA, ISO 27001, and SOC 2.
Keeping your content, user, and customer information safe is paramount, and we take it seriously. Compliance is one of the things that sets vablet apart: a trusted, validated enterprise platform that scales from large multinational operations down to small medical device distributors.

Four frameworks. Documentation ready for your review.

GDPR
CompliantData privacy regulations in Europe can be tricky. vablet has it all under control.

HIPAA
Safeguards in placevablet supports the use and distribution of your HIPAA-regulated content.

ISO 27001
CertifiedISO/IEC 27001 specifies requirements for an information security management system (ISMS).

SOC 2
AttestedYour managed data is secure, available, has processing integrity, is confidential, and private.
Not a feature we bolted on. The foundation the platform is built on.
Built for teams that cannot afford a content mistake
Most sales enablement tools were built for software companies selling software. vablet was built for pharmaceutical reps, medical device distributors, financial services advisors, industrial manufacturers, and field service organizations. In those industries, an out-of-date spec sheet, an unapproved claim, or a PDF left on a lost iPad is not an inconvenience. It is a regulatory event.
What compliance actually means for your content
Three promises: the right people see the right content, the wrong people never do, and you can prove both after the fact. vablet delivers approved content to the field, keeps every device current with the latest approved version, and gives marketing, legal, and MLR teams control over what is in circulation at any moment.
Built to satisfy your security review, not just your sales team
Enterprise buyers run vendor security assessments, procurement reviews, and IT questionnaires before a single user is provisioned. vablet has been through those reviews with global enterprises across regulated industries, and our certifications and documentation are ready for yours. A ten-person distributor gets the identical security posture as a global manufacturer.
Marketing controls it. Reps present it. The record shows it.
Approval windows and expiry are enforced on the device, even offline. Every access is recorded.

The approved library, with or without a connection
Everything a rep can open has already been approved. Expired assets disappear on their own, even offline.

Same library, light or dark, any device
iPad, iPhone, Android, and Windows. Nothing for the customer to install.

Approval window, audience, device rules: set once
Date range, groups, auto push and revoke on group change, download priority, and device restrictions on every file.
What each one is, and what vablet does about it.
What is GDPR, and how does vablet support it?
The General Data Protection Regulation (GDPR) is the European Union’s data privacy law. It governs how organizations collect, store, process, and delete the personal data of EU residents, and it gives individuals rights over that data, including the right to access it and the right to have it erased. For a sales enablement platform, GDPR touches everything from the contact details a rep captures in a follow-up form to the analytics you collect on how a prospect engaged with a presentation. vablet supports GDPR requirements so your European operations can use the platform with confidence. See our Data Processing Policy and Privacy Policy for detail.
What is HIPAA, and how does vablet support HIPAA-regulated content?
The Health Insurance Portability and Accountability Act (HIPAA) is the U.S. law that protects sensitive patient health information from being disclosed without the patient’s knowledge or consent. Medical device and pharmaceutical field teams routinely work near, and sometimes with, HIPAA-regulated material. vablet provides content controls for regulated teams. Before using protected health information, review your proposed workflow, safeguards, and any required business associate agreement with vablet and your compliance team. Learn more about how we support pharmaceutical and medical device sales teams.
What is ISO 27001, and why does it matter?
ISO 27001 is the leading international standard for information security management systems (ISMS). It is not a checklist a vendor fills out about itself. It is a framework for how an organization identifies risk, applies controls, and continually improves its security program, verified against a published standard. Certification scope matters when evaluating which services and operations are covered.
What is SOC 2, and what does it cover?
SOC 2 is an assurance reporting framework developed by the AICPA. Reports address controls relevant to the trust services criteria included in the engagement. vablet is SOC 2 attested. Request the current report to review the system scope, criteria covered, report type, and period rather than assuming every criterion is included.
Compliance questions we hear most.
Is vablet GDPR compliant?
Yes. vablet supports GDPR requirements for the handling of personal data belonging to EU residents, covering the content, user, and customer information managed in the platform.
Can vablet be used with HIPAA-regulated content?
vablet provides content controls for regulated teams. Before using protected health information, confirm the applicable workflow, safeguards, and any required business associate agreement with vablet and your compliance team. HIPAA is not a product certification.
Is vablet ISO 27001 compliant?
Yes. vablet is ISO 27001 certified. The standard addresses information security management systems. Request the current certificate to review which services and operations its scope covers.
Is vablet SOC 2 compliant?
vablet is SOC 2 attested. Request the current report to review its scope, trust services criteria, report type, and period.
Is vablet only for large enterprises?
No. vablet is a trusted, validated enterprise platform that scales from large multinational operations to small medical device distributors. A small distributor team runs on the same platform and security controls as a global manufacturer.
Which industries rely on vablet for compliant content delivery?
vablet is used by teams in pharmaceutical and medical device sales, financial services, manufacturing and distributor sales, field services and maintenance, and other regulated environments where content control is not optional.
Will vablet pass our enterprise security review?
vablet has been through enterprise vendor security assessments with global organizations in regulated industries. If your IT or security team has a questionnaire, vablet is ready for it.
Send the questionnaire. We are ready for it.
vablet has been through enterprise vendor security assessments with global organizations in regulated industries. If your IT or security team has a questionnaire, we will get you what you need.
SOC 2 attested. ISO 27001 certified. GDPR compliant. HIPAA safeguards.