Trust Center

Security, in the open

The controls, documents, and architecture your security and procurement teams need, with honest status on every line.

Data ownership

You own the keys

Bring your own keys

Run Ozen on your own model and data keys. We never sit between you and your providers.

Your data stays yours

Outcome data lives in your datastore. The signal-to-deal graph is yours, not ours.

No training on your data

Your accounts, messages, and results are never used to train models for anyone else.

Controls

Every control, honest status

Certifications

  • SOC 2 Type IIIn progress
  • GDPRAvailable
  • CCPAAvailable
  • Data Processing AgreementAvailable
  • ISO 27001Planned
  • HIPAAPlanned

Data protection

  • Encryption in transit (TLS 1.2+)Available
  • Encryption at rest (AES-256)Available
  • Bring your own keys (BYOK)Available
  • Data stays in your datastoreAvailable
  • No training on your dataAvailable
  • Data residency US / EUIn progress

Access & identity

  • SSO / SAMLAvailable
  • Role-based access controlAvailable
  • Granular send & booking permissionsAvailable
  • Audit logsAvailable
  • MFA enforcementAvailable
  • SCIM provisioningIn progress

Infrastructure

  • Tenant isolationAvailable
  • 99.9% uptime targetIn progress
  • Sub-processor listAvailable
  • Continuous monitoringAvailable
  • Independent penetration testingIn progress
  • Incident response (72h notice)Available
Sub-processors

Who we rely on

Cloud hostingApplication hosting and computeUS / EU
Model providersLLM inference (BYOK supported)US / EU
Email deliveryOutbound email sendingUS / EU
Error monitoringApplication reliabilityUS / EU
Documents

Ready for your review

Security overview

Architecture, controls, and data flows

Download

Data Processing Agreement (DPA)

GDPR Article 28, with sub-processor list

On request

SOC 2 Type II report

Available once the audit completes

In progress

Reliability

  • + 99.9% uptime target on enterprise plans
  • + Continuous monitoring and alerting
  • + Documented incident response, breach notice within 72 hours

Responsible disclosure

Found a vulnerability? We want to hear from you. Email alen@ozenlabs.ai and we will acknowledge within one business day. We do not pursue good-faith researchers.

Into your security review

Send your questionnaire. We will turn it around fast.