Honest about where we are — and aren’t
Serious buyers reward a vendor who draws the line clearly. Here’s exactly what we offer today for your compliance programme, and what’s on the roadmap — no badges we don’t hold.
What we give your programme now
EU hosting & residency
Our managed service is hosted in the EU (Frankfurt). Self-host and you choose the jurisdiction entirely — including air-gapped.
Encryption controls
End-to-end encrypted, server-blind messaging (IETF MLS / RFC 9420); encrypted transport everywhere; access control, NDA gating and audit logging.
GDPR & a DPA
We operate as a data processor for the metadata and non-E2EE content we handle, with a data-processing agreement covering sub-processors, residency, retention and breach notification.
Self-host = your boundary
Deploy on your own estate and regulated data stays inside the controls you have already certified — no external subprocessor to add to scope.
Where we’re headed, in order
We publish the roadmap rather than imply a status. Design partners move it forward.
GDPR data-processor posture + DPA
Available today for the hosted service.
Security whitepaper
A review-ready document describing exactly what is protected and how — available on request.
Independent audit of our integration
The MLS library we use is independently audited; an independent audit of our own integration, deployment and the meeting E2EE path is our top security investment with design partners.
SOC 2 Type 1
Our first formal certification target as we land regulated design partners.
ISO 27001 & sector schemes
ISO 27001 and sector-specific schemes follow, prioritised by the industries we serve.
Compliance questions
Is Ollasync SOC 2 or ISO 27001 certified?
Not yet, and we won’t imply otherwise. We provide the technical controls and a DPA that a compliance programme needs, and self-hosting keeps regulated data inside your own certified environment. SOC 2 Type 1 is our first certification target.
Can Ollasync support a HIPAA or GDPR programme?
Yes — as controls, not a certificate. Encryption, access control, audit logging, EU or on-premise hosting and a DPA give your programme what it needs. When you self-host, regulated data never leaves your audited environment.
Who are your sub-processors?
For the hosted service, sub-processors and their roles are listed in the DPA. When you self-host, there are effectively no sub-processors in the data path — you operate everything.
Can we get the security whitepaper and DPA?
Yes. Both are available on request for your security and legal review — just contact us.
Bring us your security review.
Request the security whitepaper and DPA for your legal and compliance teams, or talk to us about a self-hosted deployment inside your own boundary.