Zero credit card required — try now
Compliance & data protection

Built for your compliance programme

Serious buyers reward a vendor who draws the line clearly. Here’s exactly what we offer today for your compliance programme, and what’s on the roadmap

Today

What we give your programme now

Private by default

Recordings and documents live in private storage behind short-lived signed links, with access control you can point to in a review.

Encryption controls

End-to-end encryption for meetings (media + chat), encrypted transport everywhere, plus access control, NDA gating and audit logging.

GDPR & a DPA

We operate as a data processor for the metadata and content we handle, with a data-processing agreement covering sub-processors, residency, retention and breach notification.

Audit trails

Deal rooms and recordings carry access logs — who joined, who viewed, who downloaded — reviewable by design.

Certification roadmap

Where we’re headed, in order

We publish the roadmap rather than imply a status. Design partners move it forward.

Available

GDPR data-processor posture + DPA

Available today for the hosted service.

Available

Security whitepaper

A review-ready document describing exactly what is protected and how — available on request.

In progress

Independent security audit

An independent third-party audit of our platform, deployment and the meeting end-to-end path is our top security investment as we bring on regulated customers.

In progress

SOC 2 Type 1

Our first formal certification target as we land regulated customers.

Planned

ISO 27001 & sector schemes

ISO 27001 and sector-specific schemes follow, prioritised by the industries we serve.

FAQ

Compliance questions

What does Ollasync provide for a compliance programme?

The technical controls and a DPA that a compliance programme is built on — encryption in transit with end-to-end encryption available, role-based access control and audit logging.

Can Ollasync support a HIPAA or GDPR programme?

Yes — as controls, not a certificate. Encryption, end-to-end encryption, access control, audit logging and a DPA give your programme what it needs.

Who are your sub-processors?

For the hosted service, sub-processors and their roles are listed in the DPA, available for your legal review.

Can we get the security whitepaper and DPA?

Yes. Both are available on request for your security and legal review — just contact us.

Bring us your security review.

Request the security whitepaper and DPA for your legal and compliance teams, or bring your questions to a call.

Request whitepaper & DPA Read the security model