Enterprise-grade security you can trust.
Viva runs an ISO 27001-aligned program for executives whose EA has exposure to highly sensitive information. NDA-bound talent, MFA, encrypted credentials, no local storage, and structured onboarding and offboarding on every engagement.

Signed NDA and background check through Certn and Checkr before any access is granted.
OnboardingLeast-privilege permissions, MFA enforced, credentials in an encrypted vault. No local storage.
Least-privilegeWhy this matters
An EA has exposure to highly sensitive information.
Calendar, inbox, financials, internal documents, board materials, vendor contracts. The security model has to match the access. We built ours from the ground up to govern that access, not assume the people on either side will get it right by default.
Confidentiality by default
Every EA signs a binding NDA before they receive any access. Identity and background verification, run through Certn and Checkr, confirm the right person is supporting the right executive.
- NDA signed before onboarding
- Background and identity verification through Certn and Checkr
- Confidentiality training in Viva University
- Quarterly phishing simulations and security awareness training
Right access for the work
Your EA is proactive by design. We pair that with disciplined access. You decide what your EA can reach, and permissions follow least-privilege so the access matches the work, nothing more.
- Scoped permissions, executive-defined
- Encrypted credential management, no shared passwords
- MFA enforced across supported tools
- Device encryption (FileVault, BitLocker) on every EA workstation
Auditable activity
Every access change is logged with date, owner, and purpose. Permissions are reviewed on a quarterly cadence. When the relationship ends, credentials are removed promptly and systematically.
- Logged access changes with named owners
- Quarterly permission reviews
- Documented change controls
- Systematic credential removal at offboarding
Continuity and response
If an EA becomes unavailable, structured backup keeps work moving without unmanaged access. If a security event happens, escalation goes directly to Viva leadership through a dedicated support channel.
- Backup coverage during PTO or extended leave
- Direct escalation to Viva leadership for security events
- Dedicated support email monitored by the security team
- Defined escalation and mitigation paths

How we map to ISO 27001
The controls behind the program
Viva’s information security program is aligned with ISO 27001 principles. Here’s how the headline domains map to concrete operational controls.
| ISO 27001 Domain | How Viva implements it |
|---|---|
| Access control | Identity-based gating. Single-source provisioning tied to executive sign-off. Time-boxed sessions, automatic MFA challenge on new devices, and zero shared-credential workflows across the EA toolchain. |
| Human resource security | Verified candidates, ongoing accountability. Pre-hire screening through Certn and Checkr, signed code of conduct, quarterly security awareness refreshers, and documented acceptable-use policies that follow the EA through every engagement. |
| Asset management | Hardware governance. Viva-issued devices with full-disk encryption (FileVault, BitLocker), centralized inventory, and remote-wipe capability. Customer documents never persist on EA personal devices. |
| Operations and change control | Workflow-driven changes. Onboarding and offboarding execute through standardized runbooks. Permission changes carry timestamps, requesters, and approvers, with rollback steps documented for every action. |
| Supplier and third-party security | Curated tool stack. Every tool the EA uses passes a security review before it enters the workflow. MSA and DPA available for customers with their own compliance frameworks, plus support for customer-mandated tooling. |
| Threat readiness | Active testing, not just policy. Quarterly phishing simulations across the EA workforce, anti-malware monitoring on every device, and security drills that surface gaps before a real event finds them. |
| Incident management | Direct escalation, named owners. Security events route to Viva leadership through a dedicated support channel. Initial mitigation, customer notification, and root-cause review follow a documented playbook. |
| Continuity | Coverage that holds. Pre-trained backup EAs activate when your primary is unavailable. Customer context transfers through documented handoffs, not ad-hoc sharing. |
| Compliance and review | Recurring audits, available evidence. Quarterly access reviews, annual policy refresh, GDPR-aligned data handling. Compliance documentation and a completed security questionnaire shipped to customer security teams on request. |
Trusted by 300+ executives at scaling companies
















The access lifecycle
From day one to offboarding, access is governed.
Onboarding without controls, stale credentials after an exit, permissions that quietly expanded over time. We treat every transition as a structured event with documented steps and named owners.
Scoped access
Access provisioned through a documented workflow
- NDA signed and verified
- Executive-scoped permissions defined
- MFA configured on supported tools
- Encrypted credential vault set up
- Equipment provisioned and tracked
Reviewed and logged
Access stays appropriate as the relationship evolves
- Quarterly permission reviews
- Logged access changes with named owners
- Documented change controls
- Backup coverage for PTO and leave
- Direct escalation channel for security events
Systematically revoked
No stale credentials, no quiet access
- Credentials removed promptly
- Equipment returned and wiped
- Access logs preserved for review
- Documented sign-off from Viva and the customer
- Optional transition to a replacement EA
Common questions
What security teams ask before signing
Are you SOC 2 or ISO 27001 certified?
Viva does not operate proprietary software, so traditional SaaS audit certifications don’t apply directly. Our information security program is aligned with ISO 27001 principles, with documented controls across the domains a typical ISO audit covers. We can walk your security team through the controls in detail and provide a security questionnaire response on request.
Where is customer data stored?
EAs work directly in your tools, your tenants, and your accounts. We don’t centralize or duplicate your data on Viva infrastructure. Credentials are stored in encrypted password management, and customer documents are not stored on EA personal devices.
What happens to access when an EA leaves?
Credentials are removed promptly and systematically through our documented offboarding workflow. Equipment is returned and wiped. Access logs are preserved. We sign off with you that revocation is complete. If you’re transitioning to a replacement EA, your context carries forward but the access provisioning starts fresh.
How do you handle incident response?
Security events escalate directly to Viva leadership through a dedicated support channel monitored by our security team. We provide initial mitigation, customer notification per our security and breach notification protocol, and a documented root-cause review. Escalation paths are pre-defined with named owners.
Can we sign an MSA and DPA?
Yes. Our standard contracts include an MSA and a DPA aligned with GDPR requirements. For customers in regulated industries or with their own compliance frameworks, we accommodate additional controls and review your specific requirements during the engagement.
How do you support Zero Trust environments?
For customers operating Zero Trust architectures, we apply least-privilege access, continuous verification of permissions, segmentation between customer environments, and device and identity controls through MFA and approved devices. We calibrate the model to your environment rather than imposing a one-size-fits-all approach.
Delegate with confidence.
Get a walkthrough of our security controls and see how Viva fits into your environment.