Trust Center
A single public entry point for how OllieSafe protects customer data, where it lives, which vendors process it, and how to request procurement materials. Status-honest: we publish what ships today and what remains in progress.
Built for audit-ready safety operations.
The platform is designed to support regulated workflows, secure data isolation, and enterprise review without forcing teams back into binders, screenshots, and spreadsheet handoffs.
Status-honest Trust Center — not a completeness claim.
This page consolidates public trust topics and links. It is not a claim that a trust center is complete, that third-party security attestations have issued, or that every enterprise integration is live. Certifications and accessibility roadmaps stay on /security and /accessibility.
Start here
- Security overview — encryption, tenant isolation, audit logging, certifications roadmap, and responsible disclosure.
- Sub-processors — public list of vendors that process customer data, with categories and change-notification commitment.
- Data Processing Addendum — baseline DPA scaffold (template; Legal execution is out-of-band).
- Service Level Agreement — uptime and credit scaffold for enterprise review.
- Accessibility — WCAG 2.2 Level AA target and current conformance posture (partially conformant; VPAT remains on request / in progress).
- Service status — draft availability targets and how we communicate incidents.
Data residency
Primary application infrastructure (Cloud Run, Cloud SQL, primary filing artifact storage) operates in Google Cloud us-west1(United States). Multi-region customer-data fan-out is not a product feature today. AI embeddings use Vertex AI; text inference currently uses Google's Generative Language API, with a planned migration to Vertex customer-managed terms that is not complete. Full declaration details and AI endpoint honesty are summarized on /security (Data residency). Procurement teams may request the internal residency declaration via Ollie@olliesafe.com.
Data Processing Addendum (DPA)
A baseline DPA template (EU SCCs Module 2, UK IDTA, CCPA service-provider terms) is published at /legal/dpa. The public page is a scaffold for review; executed customer DPAs are countersigned out-of-band by Legal. Engineering materials do not substitute for Legal execution. Request an executable copy or submit redlines at Ollie@olliesafe.com.
Sub-processors
OllieSafe uses a small set of sub-processors (cloud infrastructure, identity, billing, communications). The authoritative public list — including categories of personal data processed, processing location, and a 30-day change-notification commitment — is at /legal/subprocessors.
Support access and break-glass
Customer support prefers guided screen-share without operator impersonation. When tenant impersonation is required, it is limited to platform operators on a company email domain, rate-limited, and written to a platform audit log (start/stop events). Break-glass infrastructure access (cloud console / database / secret manager) is reserved for named production owners during severity-1 recovery and follows a two-person process. Support access is least-privilege and ticketed — not unrestricted production access for all engineers.
Buyers in active procurement can request the support-access / break-glass procedure summary under NDA by emailing Ollie@olliesafe.com.
Vulnerability disclosure
We welcome good-faith reports from security researchers. Send findings to Ollie@olliesafe.com. Our machine-readable contact is at /.well-known/security.txt (RFC 9116). We follow a 90-day coordinated disclosure window from initial triage. Full researcher guidelines live on /security.
AI governance
OllieSafe's AI is governed by design, and the controls are product behavior, not policy prose. A person controls the record: AI output is a draft until a named person reviews and approves it — nothing AI-generated becomes the record on its own. Citations are verified:regulatory citations are checked against the jurisdiction's regulation text, and anything that cannot be verified is flagged for human review rather than presented as authoritative. Disclosure by default: AI surfaces identify themselves, AI-assisted drafts are labeled as pending review, and approved records carry a reviewed-and-approved attribution. The full control set, including fallback behavior when verification is unavailable, is documented on the AI governance page.
Certifications and attestations
OllieSafe does not hold a third-party security attestation today. SOC 2 Type II is in progress (Type II target Q3 2026). ISO 27001 evaluation is planned after SOC 2 Type II issuance. ISO/IEC 42001 (AI management systems) evaluation is on the roadmap alongside it, reflecting the AI-governance controls above. HIPAA / BAA is not in scope today. See the certifications roadmap on /security. Do not treat this Trust Center as proof of completed certification.
Engineering verification
Third-party attestations are one kind of trust; day-to-day engineering evidence is another. OllieSafe runs a continuous verification program over the platform itself: every module claim is backed by machine-generated receipts from real test batteries that re-run in CI, required evidence artifacts are signed under a managed cloud key into a single evidence tree, and workers' comp first-report form packs pass a seven-point deterministic certification gate on every build. Reliability and AI-governance behavior are exercised against the running platform with authenticated probes — not only unit tests — and when a check cannot be satisfied honestly it is recorded as an open item, never marked green.
A point-in-time engineering verification certificate summarizing the currently verified module set (17 modules as of July 2026), with the repository and signed-evidence anchors needed to re-derive it, is available to customers and buyers in procurement via Ollie@olliesafe.com. It is an engineering evidence artifact, not a third-party attestation, and does not replace the certifications roadmap above.
Procurement packet
Enterprise buyers can request a deal-minimum trust packet (security overview, isolation summary, privacy / DPA stance, IR/DR posture, and held-claim fences) via Ollie@olliesafe.com. Signed legal exhibits and full questionnaire packs are handled case-by-case with Legal and Security — not all artifacts are self-serve public downloads yet.
What we do not claim here
- That a trust center is complete or that every trust artifact is public.
- That OllieSafe is SOC 2 certified, or that a VPAT / WCAG AA program is complete.
- That all enterprise integrations (SSO, SCIM packages, and related buyer-live federation) are live.
- Multi-region customer data residency or customer-selectable region pinning beyond the current us-west1 posture.
Contact
Security and trust: Ollie@olliesafe.com. Privacy and data-subject requests: Ollie@olliesafe.com. Legal and contract: Ollie@olliesafe.com.