Your financial data, protected.
Victally handles sensitive tax and financial information. We take that responsibility seriously — built on enterprise-grade, independently audited infrastructure.
Last updated: June 2026
Certified infrastructure
Victally is built on the Base44 platform, which maintains independent, third-party security certifications covering hosting, encryption, and platform access.
SOC 2 Type II
An independent audit of how data and systems are protected over time (not just a single point in time). Enterprise partners can request the full report under NDA via the Base44 Trust Center.
ISO 27001
An international standard for managing information security across people, processes, and technology — confirming a repeatable, audited security management system.
How we protect your data
Encryption
Your data is encrypted in transit (TLS) and at rest, using industry-standard methods.
Data isolation
Every record is scoped to its owner. Access controls (row-level security) ensure one user can never read, edit, or delete another user's financial data — even by guessing a record ID.
Authentication
Authentication is managed by Base44's built-in, industry-standard system. Sessions are protected and your account is secured with strong authentication controls.
Clickjacking protection
Victally cannot be embedded inside another website, protecting you from clickjacking and spoofed-page attacks.
Your right to deletion
You own your data. You can request permanent deletion of your account and all associated financial records at any time by contacting us at support@movingforwardsmallbusiness.com.
For enterprise partners
If your procurement or security team requires compliance documentation (SOC 2 report, DPA, security questionnaires), reach out to support@movingforwardsmallbusiness.com. The underlying platform's SOC 2 Type II report is available under NDA through the Base44 Trust Center.