Compliance & Security

Security Built for Financial Workflows

Role-based access control, immutable audit trails, encryption at rest and in transit, and tenant isolation. Formal certifications are on the roadmap; controls are shared under NDA.

See Security Details

SOC 2 (roadmap)

Controls are designed and operated against SOC 2 criteria for security, availability, and confidentiality. Formal Type II attestation is on the security roadmap and is not yet complete.

ISO 27001 (roadmap)

The information security management program follows ISO 27001 practices for data handling, access control, and incident response. Certification is planned, not yet attested.

Controls under NDA

Control implementations, policies, and the certification roadmap are shared directly with prospective customers under NDA.

Security Control Matrix

Comprehensive security controls across access management, data protection, audit monitoring, and file security.

Access Control

  • 13 system roles with permission matrix
  • Multi-factor authentication
  • Session timeout management
  • IP allowlisting
  • Break-glass emergency access

Data Protection

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Tenant isolation via orgId
  • Field-level encryption for PII
  • 90-day data lifecycle

Audit & Monitoring

  • Immutable audit trail (append-only)
  • 90+ automated security tests
  • Real-time breach detection
  • Session lifecycle logging
  • Change management tracking

File Security

  • Malware scanning (PE/ELF/VBA)
  • CSV formula injection detection
  • File extension whitelist
  • SHA-256 checksum verification
  • Signed URL access (15-min expiry)

Frequently Asked Questions

Is the platform SOC 2 or ISO 27001 certified?
Not yet. Formal third-party certifications (SOC 2, ISO 27001) are on the security roadmap and are not yet attestable. Controls are designed against those frameworks today, and control implementations plus the certification timeline are shared with prospective customers under NDA.
How does RBAC work in Olycor?
13 system roles with a granular permission matrix. Roles are bound to users per organization. Separation of duties prevents single-user execution of sensitive operations. Step-up authentication for critical actions.
What does the immutable audit trail capture?
Every data access, modification, export, login, permission change, and configuration update. Entries are append-only (cannot be modified or deleted). Includes actor, timestamp, action, resource, and IP address.
How is data encrypted?
AES-256 encryption at rest for all stored data. TLS 1.3 for data in transit. Field-level encryption for PII fields. Tenant isolation via orgId ensures no cross-organization data access.
What is break-glass access?
Emergency access mechanism requiring four-eyes approval (two authorized users must approve). Creates a time-limited elevated session with full audit logging. Used for incident response only.

Security You Can Trust

Built for regulated financial services from day one. Not bolted on after the fact.

Get Started