Resources
Access security, compliance, governance, and architecture documentation relevant to evaluating the Optymyze platform and services.
Security and Trust
Enterprise-grade security controls, monitoring, governance, and operational safeguards designed to protect applications, infrastructure, and customer data.
Governance and compliance
Automated governance and compliance to control and continuously audit access to, use of and changes to users, roles, apps, data, processes and objects in the platform.
SOC1 Type 2 Report
Independent assessment of controls supporting operational integrity and financial reporting processes.
SOC2 Type 2 Report
Independent validation of security, availability, and confidentiality controls across the Optymyze platform and operations.
SonarSource Report
Independent source code quality and security analysis supporting secure development practices.
Penetration Testing Report
Independent penetration testing assessment evaluating external security posture and network resilience.
Subprocessors
Transparency into third-party providers supporting the hosting, operation, monitoring, and delivery of Optymyze cloud services.
AWS
Cloud infrastructure provider supporting secure hosting, scalability, availability, and data processing operations.
Office 365
Enterprise productivity, communication, collaboration, and documentation management services.
Entra ID
Identity and access management services supporting authentication and user access controls.
Monitoring
Compliance
Independent assessments, regulatory alignment, and assurance practices supporting enterprise security, privacy, governance, and operational compliance requirements.
SOC 1 Type 2
Independent assessment of controls supporting financial reporting processes.
SOC 2 Type 2
Independent validation of security and availability controls.
HIPAA
Practices supporting protected health information (PHI) safeguards.
GDPR
Privacy practices aligned to EU data protection requirements.
PIPEDA
Practices supporting Canadian privacy requirements.
CCPA
Practices supporting California consumer privacy requirements.
Third-Party Risk Exchange
Enterprise risk and security assessment information available through the ProcessUnity Global Risk Exchange.
Risk Posture
Validated enterprise security posture supported by comprehensive controls, governance, and operational safeguards.
Control Frameworks
Security controls aligned to recognized frameworks and continuously assessed against enterprise requirements.
Continuous Assurance
Ongoing monitoring and external risk intelligence supporting operational resilience and cybersecurity readiness.
