Security & compliance
Optracore was designed for regulated industries and enterprises with stringent security requirements. Our security posture is independently audited and continuously validated.
Independently audited annually. Full report available to customers and prospects under NDA.
Certified information security management system covering all production systems and data handling processes.
BAA available for healthcare customers. Optracore supports HIPAA-compliant telemetry pipelines with PHI isolation.
All data in transit is protected with TLS 1.2+ with perfect forward secrecy. All data at rest is encrypted using AES-256. API-to-API communication between internal services uses mutual TLS (mTLS).
Encryption keys are managed through our dedicated key management service with quarterly rotation, hardware security module (HSM) backing, and full key ceremony audit trails.
Optracore enforces role-based access control (RBAC) at every layer. API keys are scoped to minimum required permissions. SSO via SAML 2.0 and OIDC is supported for all Enterprise plans.
Internal access to production systems requires multi-factor authentication, VPN, and just-in-time privilege escalation with full audit logging of every privileged session.
We operate a continuous vulnerability management program including automated dependency scanning, SAST/DAST in CI/CD, and quarterly third-party penetration testing by independent security firms.
Critical vulnerabilities are remediated within 24 hours. High severity within 7 days. All findings are tracked and closed before next quarterly audit.
Enterprise customers can specify data residency to US, EU, or APAC regions. Data processed in your chosen region will never leave that region for storage or processing.
Optracore is GDPR compliant. Data processing agreements (DPA) are available for all customers. We do not sell, share, or use customer data for advertising or model training.
We take security reports seriously and respond within 24 hours. Please email security@optracore.com with details. We operate a responsible disclosure policy and offer recognition for valid findings.