1. Our approach
Security is part of how we ship — not a bolt-on. Every change goes through code review, automated security testing, and a deployment pipeline with audit logging. We use defense-in-depth so a single failure never compromises customer data.
2. Infrastructure
OVirtual runs on AWS across multiple regions with isolated VPCs. EU data residency is available on Business plans. Production environments are fully separated from staging and development. Cloudflare provides WAF, bot mitigation, and DDoS protection at the edge.
3. Encryption
- In transit: TLS 1.2+ everywhere. HSTS enabled. Certificate transparency monitoring.
- At rest: AES-256 for databases, object storage, and backups. Keys are managed in AWS KMS with rotation.
- Field-level: Sensitive fields (e.g., payment metadata) are envelope-encrypted with workspace-specific keys.
4. Access control
- SSO/SAML and SCIM provisioning on Business plans.
- MFA required for all OVirtual employees.
- Least-privilege IAM with quarterly access reviews.
- Customer audit logs cover sign-ins, permission changes, and admin actions.
5. Application security
- SAST (Semgrep) and dependency scanning on every PR.
- DAST against staging weekly.
- External penetration tests quarterly by an independent firm.
- Bug bounty program for severity 1–3 issues.
6. Monitoring
Centralized log aggregation feeds a SIEM with 24/7 alerting. Anomaly detection on authentication patterns, privilege escalation, and exfiltration signals. We retain security logs for 12 months.
7. Incident response
We follow a documented runbook: detect → contain → eradicate → recover → review. Affected customers receive notification within 72 hours of confirming a breach, with details required by Article 33(3) GDPR. Post-mortems are shared with impacted customers.
8. Business continuity & disaster recovery
Daily encrypted backups, replicated across regions. Recovery objectives: RTO 4 hours, RPO 15 minutes. We exercise restore procedures quarterly.
9. People & training
Background checks for all hires. Annual security and privacy training. Phishing simulations. Confidentiality and IP assignment in every employment contract.
10. Vendor management
Subprocessors undergo a security review before onboarding (SOC 2 / ISO 27001 reports, DPA execution, penetration test summaries). See our subprocessor list.
11. Compliance
- SOC 2 Type II — audit in progress (Type I complete).
- GDPR, UK GDPR, CCPA, PIPEDA.
- PCI-DSS via Stripe (we never see card numbers).
- TCPA, CASL, 10DLC compliance tooling built in.
12. Vulnerability disclosure
Found a security issue? We want to hear about it. Report responsibly to [email protected] (PGP key on request). Good-faith research is welcome — we will not pursue legal action against researchers who follow our safe-harbor guidelines.
Safe-harbor scope
- No automated scanning that degrades service.
- No accessing data that isn't yours.
- Give us reasonable time to fix before public disclosure (90 days).
13. Contact
Security questions, audit requests, or compliance documents: [email protected].