Security & Compliance
How We Keep Your Odoo Data Safe
Everything an enterprise procurement team needs to evaluate Octura: hosting infrastructure, encryption, access controls, sub-processors, and an honest account of what we can't yet certify.
The four pillars
Four commitments anchor our security model. Every engagement is measured against them, and any gap, intentional or not, gets documented for procurement.
Encryption everywhere
Data travels under TLS 1.2+ and rests under AES-256 encryption, with customer-managed keys available on Enterprise hosting tiers.
Data residency
Choose your hosting region, AWS or GCP, in the US, Canada, or EU, and your data stays put; it never crosses borders without written approval.
Least-privilege access
Access is role-based across Odoo and our infrastructure, every engineer account carries MFA, and every production action is logged.
Honest compliance posture
We're GDPR-aligned today, working through SOC 2 Type I, and have ISO 27001 on the roadmap, and we're clear about what's finished versus underway rather than implying certifications we don't hold.
Control categories
Access & Identity
Governs who can do what, from where, and when, across both Odoo and the hosting layer.
- MFA mandatory on every Octura engineer account
- Role-based access in Odoo (sales, finance, technical) with named groups
- Time-bound break-glass access for production with 24h auto-expiry
- Quarterly access review and removal of dormant accounts
Network & Infrastructure
Our AWS and GCP hosting is hardened to enterprise standards.
- Private VPC with separate subnets for app, database, and management
- WAF (Cloudflare or AWS WAF) with rate limiting and bot mitigation
- Optional IP allow-list and site-to-site VPN for production access
- DDoS protection via Cloudflare Magic Transit on Enterprise tiers
Data Protection
Covers encryption, backups, and lifecycle management for the data that actually matters.
- AES-256 encryption at rest on managed volumes and database snapshots
- TLS 1.2+ enforced on all customer-facing endpoints
- Encrypted off-site backups retained for 35 days (or per SOW)
- PII data masking in non-production environments by default
Compliance & Audit
A snapshot of where we stand on the frameworks procurement teams care most about.
- GDPR-aligned data processing agreements available on request
- SOC 2 Type I audit in progress (target completion Q4 2026)
- Quarterly internal access reviews and infrastructure audits
- Penetration testing performed annually by an external firm
Backup & Recovery Targets
Recovery point and recovery time objectives, broken down by hosting tier, verified through quarterly disaster-recovery drills rather than paper guarantees.
| Hosting tier | Backup frequency | RPO (data loss window) | RTO (recovery time) |
|---|---|---|---|
| Odoo.sh | Daily incremental | 24 hours | 4 to 8 hours |
| Octura Cloud | Hourly incremental, daily full | 1 hour | 2 to 4 hours |
| On-premise | Per SOW | Per SOW | Per SOW |
Every backup is encrypted, kept in a separate region, and put through a full restore drill each quarter, with restore procedures documented per engagement and reviewed in the SOW.
Sub-processors
Here are the vendors behind our service, what each one handles, and where their data lives. Any new sub-processor that touches customer data gets a 30-day notice before we bring them on.
| Vendor | Purpose | Region(s) |
|---|---|---|
| AWS | Hosting, storage, networking, encryption keys | Customer-selected: US / Canada / EU |
| Google Cloud | Hosting, storage, networking (alternative to AWS) | Customer-selected: US / Canada / EU |
| Cloudflare | DNS, WAF, DDoS protection, edge caching | Global edge, EU control plane |
| Sentry | Error monitoring (server-side stack traces) | EU (Frankfurt) |
| Odoo S.A. | Odoo S.A. for Odoo.sh hosted deployments only | EU (Belgium) |
Vulnerability Disclosure
If you suspect a security issue affecting Octura, our infrastructure, or a customer deployment we manage, let us know. We respond within one business day and finish triage within three.
Include a description of the issue, steps to reproduce it, and how to reach you. We'll acknowledge within 24 hours, complete triage within three business days, and disclose any customer-impacting findings on the timeline set out in our technical support policy.
security@octurasolutions.comNeed our security questionnaire?
We keep answers ready for the common procurement questionnaires, CAIQ, SIG-Lite, custom forms included. Email a senior consultant and the current packet will be in your inbox within one business day.
Talk to a senior consultantSecurity FAQ
01
Are you SOC 2 certified?
SOC 2 Type I is underway, targeting completion in Q4 2026. We already align with the Trust Services Criteria, access reviews, vulnerability scanning, encryption, but won't claim certification until the audit actually closes. Procurement teams can request the in-progress evidence packet.
02
Are you GDPR-compliant?
Yes. EU customers get signed Data Processing Agreements, their data stays hosted in EU regions, and every sub-processor and its location is documented. Requests from data subjects, access, rectification, deletion, are honored within GDPR's statutory windows.
03
What happens if a sub-processor has a breach?
Sub-processor security postures are monitored on an ongoing basis. Should a confirmed breach affect customer data, impacted customers are notified within 72 hours, consistent with GDPR Article 33 and our technical support policy.
04
Can we audit your environment?
Yes. With 30 days' notice, Enterprise customers can run a documented security audit against our environment once a year, and scope plus any compensating controls get agreed in writing before fieldwork starts.
05
What data do you retain after a contract ends?
We return customer data in a documented Odoo backup format within 30 days of contract end. From there, it's deleted from production within 90 days and from backups within 12 months, with the exact retention terms written into every SOW.