Compliance & data protection

Honest about where we are — and aren’t

Serious buyers reward a vendor who draws the line clearly. Here’s exactly what we offer today for your compliance programme, and what’s on the roadmap — no badges we don’t hold.

Today

What we give your programme now

EU hosting & residency

Our managed service is hosted in the EU (Frankfurt). Self-host and you choose the jurisdiction entirely — including air-gapped.

Encryption controls

End-to-end encrypted, server-blind messaging (IETF MLS / RFC 9420); encrypted transport everywhere; access control, NDA gating and audit logging.

GDPR & a DPA

We operate as a data processor for the metadata and non-E2EE content we handle, with a data-processing agreement covering sub-processors, residency, retention and breach notification.

Self-host = your boundary

Deploy on your own estate and regulated data stays inside the controls you have already certified — no external subprocessor to add to scope.

Certification roadmap

Where we’re headed, in order

We publish the roadmap rather than imply a status. Design partners move it forward.

Available

GDPR data-processor posture + DPA

Available today for the hosted service.

Available

Security whitepaper

A review-ready document describing exactly what is protected and how — available on request.

In progress

Independent audit of our integration

The MLS library we use is independently audited; an independent audit of our own integration, deployment and the meeting E2EE path is our top security investment with design partners.

In progress

SOC 2 Type 1

Our first formal certification target as we land regulated design partners.

Planned

ISO 27001 & sector schemes

ISO 27001 and sector-specific schemes follow, prioritised by the industries we serve.

FAQ

Compliance questions

Is Ollasync SOC 2 or ISO 27001 certified?

Not yet, and we won’t imply otherwise. We provide the technical controls and a DPA that a compliance programme needs, and self-hosting keeps regulated data inside your own certified environment. SOC 2 Type 1 is our first certification target.

Can Ollasync support a HIPAA or GDPR programme?

Yes — as controls, not a certificate. Encryption, access control, audit logging, EU or on-premise hosting and a DPA give your programme what it needs. When you self-host, regulated data never leaves your audited environment.

Who are your sub-processors?

For the hosted service, sub-processors and their roles are listed in the DPA. When you self-host, there are effectively no sub-processors in the data path — you operate everything.

Can we get the security whitepaper and DPA?

Yes. Both are available on request for your security and legal review — just contact us.

Bring us your security review.

Request the security whitepaper and DPA for your legal and compliance teams, or talk to us about a self-hosted deployment inside your own boundary.

Request whitepaper & DPA Read the security model