Home White-Label Development Course Design, SCORM & AI LMS Implementation Marketing & AI VisibilityAssociations & CEU ProvidersVenture Capital FirmsFunded Startups Guides About Testimonials Contact Book a Discovery Call →
Trust & Security

How we handle data, procurement & security

One page for whatever your legal, IT, or security team asks first: NDAs, MSAs, security questionnaires, data residency, and DPAs. Including the honest answer to the question procurement teams eventually ask directly: no, we're not SOC 2 certified, and here's exactly why that's the right framework for a services partner, not the wrong one to be missing.

Confidentiality

NDA-covered, white-label by default

NDA on every engagement

Complete discretion under NDA is standard, not an add-on. We're comfortable working through your own NDA template rather than insisting on ours.

No new names without approval

We don't add new end-client names to our own marketing without explicit approval. White-label discretion runs both directions.

Enterprise procurement

Built to clear legal review, not just IT

MSA & project-specific SOWs

We work under a Master Service Agreement with individual statements of work per project, and we're comfortable with standard enterprise legal review timelines.

Security questionnaires & vendor risk

Handled alongside your IT and security teams as a normal part of the engagement, not treated as a delay to negotiate around.

Data residency & DPA support

Data handling documented against your requirements, with a Data Processing Agreement in place before any user record moves.

SSO, SAML & identity

Single sign-on and identity provider integrations configured and tested against your IT team's actual requirements, including for AMS-LMS identity federation.

Multi-department scope

Different content, permissions, and reporting per department scoped from day one, not bolted on after a pilot outgrows its structure.

A retainer, not a one-off vendor

Most enterprise clients keep us on past launch as platforms, departments, and compliance requirements change, rather than re-scoping a new vendor each time.

What we don't claim

VertoLaunch is a professional services and delivery partner, not a SaaS platform, so we're not SOC 2 certified, and we won't pretend otherwise or bury the answer. SOC 2 evaluates a software vendor's own infrastructure and controls; the systems that actually hold your learner data are the LMS platforms you choose and control, Docebo, LearnWorlds, Cornerstone, Workday Learning, or others, and their own security posture and certifications are what apply there. Our part of the engagement is supporting your team through security questionnaires and vendor risk review, documenting data handling with a DPA, and configuring SSO and identity integration to your requirements, real accountability without a certification claim we haven't earned. Your data and content stay yours; the underlying platform stays licensed from its own vendor. We build, configure, and manage it on your behalf and don't claim ownership or infrastructure custodianship beyond the scope of the engagement.

Evaluating us for an enterprise, association, or fund-level engagement? See our LMS implementation & migration service for how this plays out on a real project, or our AMS-LMS integration guide if identity federation and credit writeback are the specific concern.

FAQ

Frequently asked questions

Yes. Every white-label engagement runs under NDA by default, and we're used to working through a client's own NDA template rather than insisting on ours.
Yes. We work through security questionnaires, vendor risk assessments, and procurement documentation as a normal part of enterprise engagements, alongside your IT and security teams rather than around them.
Yes. We're set up to work under a Master Service Agreement with project-specific statements of work, and we're comfortable with standard enterprise procurement timelines, legal review included.
Yes. Data handling is documented against your specific requirements, and a DPA is in place before any user record moves between systems, part of our standard enterprise onboarding, not a special request.
No, and we won't claim otherwise. VertoLaunch is a professional services and delivery partner, not a SaaS platform, so SOC 2 certification, which evaluates a software vendor's own infrastructure, isn't the relevant framework for what we do. The systems that actually hold your learner data are the LMS platforms you choose and control, Docebo, LearnWorlds, Cornerstone, or others, and their own security posture and certifications apply there. We support your team through security questionnaires and vendor risk review for our part of the engagement, and document data handling with a DPA, but we don't hold or claim a SOC 2 report ourselves.
You do. Your courses, your learner data, and your completion records belong to you. The underlying LMS platform itself, Docebo, LearnWorlds, Cornerstone, or whichever you use, remains licensed from its own vendor, we configure and manage it on your behalf but don't claim ownership or infrastructure custodianship beyond the scope of the engagement.
Yes. Single sign-on and identity provider integrations are configured and tested against your IT team's requirements as a standard part of enterprise LMS implementation, not left as a post-launch loose end.
No pitch. No pressure.

Have a specific security or legal question?

Book a 20-minute call and bring your security questionnaire or procurement checklist. We'll tell you honestly what we can and can't check off.

Book Your 20-Min Discovery Call