Ochroni legal
Security Overview
This page summarizes the security controls Ochroni uses to protect customer data, service access, and operational continuity.
Security, privacy, and trust questions can be directed to the contacts published here and in the legal center.
Assurance status
Ochroni has not completed an external security certification or audit. Public materials do not claim ISO, SOC, NIS2, KRITIS, or similar certification or regulated-compliance status.
Access control
Access to customer data is restricted by workspace membership, role-based permissions, and additional controls for administrative access.
Guest access
Guest join/report links are locally generated, revocable, and isolated per incident or team report flow. QR rendering stays on Ochroni infrastructure.
Transport and edge controls
Traffic is encrypted in transit, and network and application-layer protections are used to reduce unauthorized access to service routes and administrative interfaces.
Recovery
Backup and recovery procedures are maintained to support restoration, continuity, and incident response.
Procurement pack
Current hosting region, subprocessors, DPA links, backup evidence status, support contacts, and launch limitations are published in the Security and Procurement Pack.
Responsible disclosure
Report security findings to security@ochroni.com. Ochroni reviews good-faith reports and works with reporters to validate and address confirmed issues.
Responsible disclosure process
Reports should include enough detail for reproduction and assessment, such as affected URLs, steps, impact, and any suggested mitigation where available.
Please avoid activity that could interrupt service, access data without authorization, or affect other users. Ochroni aims to acknowledge reports within 2 business days and provide status updates during triage.
Security questions, vendor reviews, or procurement requests: security@ochroni.com
Machine-readable disclosure contact: /.well-known/security.txt
Legal and privacy documentation is available in the legal center.
Buyer due-diligence material is available in the Security and Procurement Pack.