Infrastructure, Security and Compliance
Infrastructure, Security and Compliance
How Virtual Front Desk is built, where your data lives and how it is protected.
Virtual Front Desk is a cloud-based visitor management and virtual reception platform built for enterprise-grade security, reliability and scale. The application runs on Microsoft Azure, and video calls use Azure Communication Services (ACS), Microsoft’s real-time communication platform.
Microsoft Azure: our infrastructure
The Virtual Front Desk application and its data are hosted on Microsoft Azure, one of the most secure and widely certified cloud platforms available. The Azure platform holds ISO/IEC 27001, SOC 2 Type II, SOC 3 and CSA STAR certifications.
You choose the region where your data is hosted when you create your account:
| Region | Dashboard address | Hosting |
|---|---|---|
| United States | app.virtualfrontdesk.com | United States |
| Canada | app.virtualfrontdesk.ca | Canada |
| Global (EU) | app.virtualfrontdesk.global | Germany, for GDPR compliance |
| Asia (AU) | app.virtualfrontdesk.asia | Australia |
To learn more, read Sign up, Regions and Sign-in Options.
Azure Communication Services: our video technology
Video calls between your stations and your users run on Azure Communication Services (ACS), built on the same global Microsoft infrastructure as Microsoft Teams. ACS provides:
- Enterprise-grade video calling, fully built into Virtual Front Desk.
- Encrypted audio and video streams for every call.
- Reliable connections worldwide through Microsoft’s global network.
Phone calls and phone fallback use Twilio Voice.
Calls are never recorded. Video calls are live only. Virtual Front Desk keeps call details and the items you capture on purpose during a call, such as screenshots, ID captures and signed documents, encrypted in your History.
How your data is protected
- Encryption: all data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 on Azure).
- Secure sign-in: users sign in with an email and password, or with single sign-on through Microsoft, Google, Apple or Okta.
- Role-based access: owners, administrators, managers and users each see and do only what their role allows. To learn more, read Organizations, owner, admin and regular users.
- Activity history: call logs and sign-in logs show who did what and when.
- Data retention: sign-in logs and call history are kept for 12 months, then deleted automatically.
- Payments: Virtual Front Desk does not store, process or transmit cardholder data. All card payments are processed end to end by Stripe.
Compliance
- SOC 2: Virtual Front Desk is SOC 2 Type I certified. Our security program is aligned with ISO/IEC 27001 and the NIST Cybersecurity Framework.
- GDPR: customers in Europe can host their data in Germany on the Global (EU) region.
- Healthcare: sign-in data is encrypted in transit and at rest on Microsoft Azure with role-based access.
Service providers
Some services that make Virtual Front Desk work are provided by trusted partners, some of them based in the United States: Microsoft Azure Communication Services (video calls), Twilio (phone calls), Auth0 (sign-in) and Google Firebase (real-time updates). A complete list of sub-processors, our Data Processing Agreement (DPA) and our security overview are available on request.
For the network access these services need, read Troubleshooting Guide, Firewall and Permissions.
Need more help?
Please contact us through the live chat.