Ochroni security
Security Overview
Ochroni uses these controls for customer data, workspace access, and service recovery.
Send security questions to [email protected].
Assurance status
Ochroni does not claim ISO 27001, SOC 2, NIS2, KRITIS, or similar certification. Buyers can review the security controls and procurement material.
Access control
Workspace membership and role permissions limit access to customer data. Administrative access uses additional controls.
Guest access
Ochroni creates guest join and report links. Each link applies to one incident or team report. Owners or admins can revoke team report links. Owners, admins, or responders can revoke incident links. The browser renders QR codes for these links.
Transport and edge controls
Ochroni encrypts traffic in transit. Network and application controls limit access to service routes and administrative interfaces.
Recovery
Ochroni maintains backup and recovery procedures. They help restore service and handle incidents.
Procurement pack
Read the Security and Procurement Pack for the current hosting region, subprocessors, DPA links, backup and recovery scope, support contacts, and assurance status.
Responsible disclosure
Send security findings to [email protected]. Ochroni reviews good-faith reports.
Responsible disclosure process
Include each affected URL. Add steps to reproduce the issue. Describe the impact.
Add a suggested fix if you have one.
Do not interrupt the service. Do not access data without authorization. Do not change another user's data.
Ochroni's response target is two business days. This target is not an SLA.
Ochroni sends updates during its review.
Security questions, vendor reviews, and procurement requests: [email protected]
Standard security contact file: /.well-known/security.txt
Read legal and privacy documents in the Legal Center.
Read buyer due diligence material in the Security and Procurement Pack.