Skip to main content
Trust Center

Trust Center

A single public entry point for how OllieSafe protects customer data, where it lives, which vendors process it, and how to request procurement materials. Status-honest: we publish what ships today and what remains in progress.

Trust & controls

Built for audit-ready safety operations.

The platform is designed to support regulated workflows, secure data isolation, and enterprise review without forcing teams back into binders, screenshots, and spreadsheet handoffs.

TLS 1.3
Encryption in transit
256-bit AES
Encryption at rest
Row-level security
Tenant isolation
MFA + RBAC
Identity controls
Hash-chained audit log
Tamper-evident history
Receipt-verified modules
Evidence re-run in CI
SOC 2 in progress
Type II target Q3 2026
GDPR-aligned DPA
Available on request

Status-honest Trust Center — not a completeness claim.

This page consolidates public trust topics and links. It is not a claim that a trust center is complete, that third-party security attestations have issued, or that every enterprise integration is live. Certifications and accessibility roadmaps stay on /security and /accessibility.

Start here

  • Security overview — encryption, tenant isolation, audit logging, certifications roadmap, and responsible disclosure.
  • Sub-processors — public list of vendors that process customer data, with categories and change-notification commitment.
  • Data Processing Addendum — baseline DPA scaffold (template; Legal execution is out-of-band).
  • Service Level Agreement — uptime and credit scaffold for enterprise review.
  • Accessibility — WCAG 2.2 Level AA target and current conformance posture (partially conformant; VPAT remains on request / in progress).
  • Service status — draft availability targets and how we communicate incidents.

Data residency

Primary application infrastructure (Cloud Run, Cloud SQL, primary filing artifact storage) operates in Google Cloud us-west1(United States). Multi-region customer-data fan-out is not a product feature today. AI embeddings use Vertex AI; text inference currently uses Google's Generative Language API, with a planned migration to Vertex customer-managed terms that is not complete. Full declaration details and AI endpoint honesty are summarized on /security (Data residency). Procurement teams may request the internal residency declaration via Ollie@olliesafe.com.

Data Processing Addendum (DPA)

A baseline DPA template (EU SCCs Module 2, UK IDTA, CCPA service-provider terms) is published at /legal/dpa. The public page is a scaffold for review; executed customer DPAs are countersigned out-of-band by Legal. Engineering materials do not substitute for Legal execution. Request an executable copy or submit redlines at Ollie@olliesafe.com.

Sub-processors

OllieSafe uses a small set of sub-processors (cloud infrastructure, identity, billing, communications). The authoritative public list — including categories of personal data processed, processing location, and a 30-day change-notification commitment — is at /legal/subprocessors.

Support access and break-glass

Customer support prefers guided screen-share without operator impersonation. When tenant impersonation is required, it is limited to platform operators on a company email domain, rate-limited, and written to a platform audit log (start/stop events). Break-glass infrastructure access (cloud console / database / secret manager) is reserved for named production owners during severity-1 recovery and follows a two-person process. Support access is least-privilege and ticketed — not unrestricted production access for all engineers.

Buyers in active procurement can request the support-access / break-glass procedure summary under NDA by emailing Ollie@olliesafe.com.

Vulnerability disclosure

We welcome good-faith reports from security researchers. Send findings to Ollie@olliesafe.com. Our machine-readable contact is at /.well-known/security.txt (RFC 9116). We follow a 90-day coordinated disclosure window from initial triage. Full researcher guidelines live on /security.

AI governance

OllieSafe's AI is governed by design, and the controls are product behavior, not policy prose. A person controls the record: AI output is a draft until a named person reviews and approves it — nothing AI-generated becomes the record on its own. Citations are verified:regulatory citations are checked against the jurisdiction's regulation text, and anything that cannot be verified is flagged for human review rather than presented as authoritative. Disclosure by default: AI surfaces identify themselves, AI-assisted drafts are labeled as pending review, and approved records carry a reviewed-and-approved attribution. The full control set, including fallback behavior when verification is unavailable, is documented on the AI governance page.

Certifications and attestations

OllieSafe does not hold a third-party security attestation today. SOC 2 Type II is in progress (Type II target Q3 2026). ISO 27001 evaluation is planned after SOC 2 Type II issuance. ISO/IEC 42001 (AI management systems) evaluation is on the roadmap alongside it, reflecting the AI-governance controls above. HIPAA / BAA is not in scope today. See the certifications roadmap on /security. Do not treat this Trust Center as proof of completed certification.

Engineering verification

Third-party attestations are one kind of trust; day-to-day engineering evidence is another. OllieSafe runs a continuous verification program over the platform itself: every module claim is backed by machine-generated receipts from real test batteries that re-run in CI, required evidence artifacts are signed under a managed cloud key into a single evidence tree, and workers' comp first-report form packs pass a seven-point deterministic certification gate on every build. Reliability and AI-governance behavior are exercised against the running platform with authenticated probes — not only unit tests — and when a check cannot be satisfied honestly it is recorded as an open item, never marked green.

A point-in-time engineering verification certificate summarizing the currently verified module set (17 modules as of July 2026), with the repository and signed-evidence anchors needed to re-derive it, is available to customers and buyers in procurement via Ollie@olliesafe.com. It is an engineering evidence artifact, not a third-party attestation, and does not replace the certifications roadmap above.

Procurement packet

Enterprise buyers can request a deal-minimum trust packet (security overview, isolation summary, privacy / DPA stance, IR/DR posture, and held-claim fences) via Ollie@olliesafe.com. Signed legal exhibits and full questionnaire packs are handled case-by-case with Legal and Security — not all artifacts are self-serve public downloads yet.

What we do not claim here

  • That a trust center is complete or that every trust artifact is public.
  • That OllieSafe is SOC 2 certified, or that a VPAT / WCAG AA program is complete.
  • That all enterprise integrations (SSO, SCIM packages, and related buyer-live federation) are live.
  • Multi-region customer data residency or customer-selectable region pinning beyond the current us-west1 posture.

Contact

Security and trust: Ollie@olliesafe.com. Privacy and data-subject requests: Ollie@olliesafe.com. Legal and contract: Ollie@olliesafe.com.

Start 30-day free trial