Skip to main content
OVirtual OVirtual
Product Features Pricing Customers FAQ
Sign in Start free→
Product Features Pricing Customers FAQ
Sign in Start free trial
Home / Security

Security

How we protect your customer conversations, calls, and business records — at every layer.

SOC 2 Type II · In progress GDPR CCPA PIPEDA PCI-DSS
Last updated · January 8, 2026
On this page
  1. Our approach
  2. Infrastructure
  3. Encryption
  4. Access control
  5. Application security
  6. Monitoring
  7. Incident response
  8. Business continuity
  9. People & training
  10. Vendor management
  11. Compliance
  12. Vulnerability disclosure
  13. Contact

1. Our approach

Security is part of how we ship — not a bolt-on. Every change goes through code review, automated security testing, and a deployment pipeline with audit logging. We use defense-in-depth so a single failure never compromises customer data.

2. Infrastructure

OVirtual runs on AWS across multiple regions with isolated VPCs. EU data residency is available on Business plans. Production environments are fully separated from staging and development. Cloudflare provides WAF, bot mitigation, and DDoS protection at the edge.

3. Encryption

  • In transit: TLS 1.2+ everywhere. HSTS enabled. Certificate transparency monitoring.
  • At rest: AES-256 for databases, object storage, and backups. Keys are managed in AWS KMS with rotation.
  • Field-level: Sensitive fields (e.g., payment metadata) are envelope-encrypted with workspace-specific keys.

4. Access control

  • SSO/SAML and SCIM provisioning on Business plans.
  • MFA required for all OVirtual employees.
  • Least-privilege IAM with quarterly access reviews.
  • Customer audit logs cover sign-ins, permission changes, and admin actions.

5. Application security

  • SAST (Semgrep) and dependency scanning on every PR.
  • DAST against staging weekly.
  • External penetration tests quarterly by an independent firm.
  • Bug bounty program for severity 1–3 issues.

6. Monitoring

Centralized log aggregation feeds a SIEM with 24/7 alerting. Anomaly detection on authentication patterns, privilege escalation, and exfiltration signals. We retain security logs for 12 months.

7. Incident response

We follow a documented runbook: detect → contain → eradicate → recover → review. Affected customers receive notification within 72 hours of confirming a breach, with details required by Article 33(3) GDPR. Post-mortems are shared with impacted customers.

8. Business continuity & disaster recovery

Daily encrypted backups, replicated across regions. Recovery objectives: RTO 4 hours, RPO 15 minutes. We exercise restore procedures quarterly.

9. People & training

Background checks for all hires. Annual security and privacy training. Phishing simulations. Confidentiality and IP assignment in every employment contract.

10. Vendor management

Subprocessors undergo a security review before onboarding (SOC 2 / ISO 27001 reports, DPA execution, penetration test summaries). See our subprocessor list.

11. Compliance

  • SOC 2 Type II — audit in progress (Type I complete).
  • GDPR, UK GDPR, CCPA, PIPEDA.
  • PCI-DSS via Stripe (we never see card numbers).
  • TCPA, CASL, 10DLC compliance tooling built in.

12. Vulnerability disclosure

Found a security issue? We want to hear about it. Report responsibly to [email protected] (PGP key on request). Good-faith research is welcome — we will not pursue legal action against researchers who follow our safe-harbor guidelines.

Safe-harbor scope

  • No automated scanning that degrades service.
  • No accessing data that isn't yours.
  • Give us reasonable time to fix before public disclosure (90 days).

13. Contact

Security questions, audit requests, or compliance documents: [email protected].

Privacy Policy →Terms of Service →Fair Usage Policy →DPA →
OVirtualOVirtual

The unified workspace for service businesses. One screen. One bill. One source of truth.

Product
Unified InboxBusiness PhoneVideoProposalsCRMHelp Center
Company
AboutCustomersCareersPressContact
Resources
BlogChangelogDocsMigrationStatus
Legal
Privacy PolicyTerms of ServiceFair Usage PolicyDPASecurity
© 2026 OVirtual Inc. Made in Toronto · Shipped daily