Skip to content

00 — SECURITY

Built for the
security review.

Every question your CIO or security officer is going to ask, answered on a public page. SOC 2 Type II, SAML SSO, SCIM, audit log, CMEK, quarterly pen-test, public subprocessor list. This is the spec; we put it on the open web so the diligence cycle is two days instead of two weeks.

0

Questions a security team has actually asked us in diligence — answered below, on the record

01POSTURE

Six pillars, then the whole spec.

The summary a security officer reads first. Everything under it is the evidence.

01Compliance

SOC 2 Type II audited annually. GDPR + CCPA compliant. PCI-DSS scoped (we don't store card data; Stripe owns it). Public-bid government contracts supported via Enterprise tier.

02Encryption

AES-256 at rest (Postgres database + Supabase Storage). TLS 1.3 minimum in transit. Customer-managed keys (CMEK) available on request for Enterprise tier.

03Access control

SAML SSO via Okta, Azure AD, Google Workspace, JumpCloud, OneLogin. SCIM provisioning (push + pull). Resource-level RBAC. JIT provisioning. Audit log retention up to unlimited.

04Infrastructure

Multi-region active-active deployment on Vercel + Supabase. AWS us-east-1 + us-west-2 default. EU data residency available on request. Database replication + automated backup every 6h.

05Reliability

99.95% uptime SLA on Enterprise (99.9% on Pro). Public status page with full incident history. SLA credits applied automatically when missed. DR tested quarterly.

06Vulnerability disclosure

Coordinated disclosure with a 90-day patch window. Researchers contact security@integrateit.tech. Bug bounty in pilot for Q3 2026 launch. Pen-test every quarter (Bishop Fox).

02 — THE FULL SPEC

Twenty answers, on the record.

Each row is a question we've actually been asked by a security team in diligence. The answers don't move — if they did, we'd version this page.

Optimus AI security controls
ControlAnswer
Compliance + encryption
SOC 2 Type IIAudited annually · report available under NDA
Encryption at restAES-256 (Postgres + Supabase Storage)
Encryption in transitTLS 1.3 minimum, perfect-forward-secrecy
Customer-managed keys (CMEK)Available on Enterprise · key rotation supported
Access control
SAML SSOOkta · Azure AD · Google Workspace · JumpCloud · OneLogin · generic SAML 2.0
SCIM provisioningPush + pull · JIT user creation · group sync
Role-based access controlResource-level · per-tenant · custom roles on Enterprise
Multi-factor authenticationTOTP · WebAuthn · enforced for admin roles
Your data
Audit log retention90 days (Pro) · unlimited (Enterprise)
Data residencyUS-East / US-West default · EU available on request
Data exportSelf-serve CSV + JSON · no exit fee
Data deletionImmediate on request · GDPR Article 17 honored
Resilience
Backup cadenceContinuous WAL + 6-hour full snapshots, 30-day retention
Disaster recoveryRPO 6h · RTO 4h · tested quarterly
Uptime SLA99.9% (Pro) · 99.95% (Enterprise) · credits automatic
Assurance
Penetration testingQuarterly third-party (Bishop Fox) · summary available under NDA
Vulnerability disclosureCoordinated · 90-day patch window · security@integrateit.tech
SubprocessorsVercel · Supabase · Anthropic · OpenAI · Stripe · published list
PII handlingField-level encryption · access logged · minimal retention
PCI scopeOut-of-scope (Stripe handles payment data exclusively)

03 — SUBPROCESSORS

Every vendor that touches your data.

Published in full. Customers are notified by email 30 days before we add or replace any subprocessor on this list.

Published subprocessors
VendorPurpose
VercelApplication hosting + edge compute
SupabasePostgres database + Storage + Auth
AnthropicPrimary LLM (Optimus AI agent)
OpenAIFallback LLM
StripeBilling + payment processing (PCI scope)
ResendTransactional email
TwilioSMS + voice notifications
Bishop FoxPenetration testing + security audit

04 — INCIDENT RESPONSE

What happens when something goes wrong.

Public status page. Per-incident root-cause analysis published within 5 business days. SLA credits applied automatically. Customer communication cadence: detection within 5 min, customer email within 30 min, full RCA within 5 business days.

Detect

≤ 5 min

PagerDuty alert + on-call engineer engaged

Notify

≤ 30 min

Status page updated + affected customers emailed

Resolve

≤ 4 h (SLA)

Service restored to baseline

RCA

≤ 5 days

Root-cause analysis published, remediation owners assigned

05 — START THE REVIEW

Pass the diligence in two days, not two weeks.

We answer security questionnaires in 48 hours and have SIG / CAIQ responses pre-filled.

Book a demoTalk