Security

Transparency about OliveOps' security architecture and safeguards

Effective Date:
August 5, 2026
Last Updated:
August 5, 2026
Estimated Read Time:
8 min read
Version:
1.0

1. Security Philosophy

At OliveOps, security is a fundamental priority. We design and operate our platform with the goal of protecting your business data, customer information, and employee records from unauthorized access, disclosure, and misuse.

This page describes our current security practices and infrastructure. We are committed to continuous improvement and will update this documentation as our security practices evolve.

2. Shared Responsibility Model

Security is a shared responsibility between OliveOps and our customers:

  • OliveOps is responsible for: Platform security, infrastructure hardening, data encryption, secure development, incident response, and monitoring
  • Customers are responsible for: Account access management, strong passwords, two-factor authentication, employee access control, data classification, and compliance with their own legal obligations

3. Account Security

OliveOps provides the following account security features:

  • Unique login credentials: Each user must have a unique username and password
  • Password requirements: We enforce minimum password complexity standards
  • Session management: Login sessions expire after a period of inactivity
  • Login tracking: We log and monitor authentication attempts for suspicious activity
  • Account recovery: Secure password reset procedures are available

4. Role-Based Access Control

OliveOps implements role-based access control (RBAC) to restrict access to data and features based on user roles and permissions. Administrators can assign different roles to team members with corresponding access levels.

Administrators are responsible for properly configuring permissions and removing access for users who no longer should have it.

5. Authentication and Session Management

Authentication: OliveOps uses secure authentication mechanisms to verify user identity. Passwords are hashed using industry-standard algorithms and are never stored in plaintext.

Sessions: User sessions are managed securely with authentication tokens. Sessions are subject to timeout periods to minimize the risk of unauthorized access.

Multi-factor authentication (MFA): Where enabled, OliveOps may support MFA to provide an additional layer of security.

6. Infrastructure and Hosting

OliveOps is hosted on cloud infrastructure provided by industry-leading providers:

  • Vercel: Application hosting and content delivery
  • AWS (Amazon Web Services): Database, storage, and related cloud services in the us-east-2 region

These providers maintain their own security practices, compliance certifications, and incident response procedures. Please refer to their security documentation for details about their infrastructure safeguards.

7. Data Transmission

Encryption in transit: All data transmitted between your browser or device and OliveOps servers is encrypted using TLS (Transport Layer Security) protocol (HTTPS). This protects data from interception during transmission.

API connections: API integrations with third-party services use secure, encrypted connections.

8. Data Storage Safeguards

Data storage: Customer data is stored in AWS DynamoDB, which is a managed database service that provides physical security, access controls, and data redundancy.

Encryption at rest: We employ encryption and access controls to protect stored data. Details about encryption implementation should be verified with our support team and applicable infrastructure documentation.

Data redundancy: AWS provides data redundancy and failover mechanisms to protect against data loss.

9. Logging and Monitoring

OliveOps maintains audit logs of system activity to detect and investigate security events. Logs include:

  • User authentication and login attempts
  • Data access and modifications
  • Administrative actions
  • System errors and exceptions

We monitor these logs for suspicious patterns and potential security incidents.

10. Secure Development Practices

OliveOps follows secure software development practices, including:

  • Code review processes
  • Security testing and quality assurance
  • Input validation and output encoding to prevent injection attacks
  • Secure error handling
  • Least privilege access for development environments

11. Dependency Management

OliveOps is built using open-source and third-party libraries. We monitor these dependencies for known vulnerabilities and apply security updates regularly.

12. Incident Response

In the event of a security incident:

  • We will investigate the incident and assess the scope of any data exposure
  • We will work to remediate the issue and prevent recurrence
  • We will notify affected customers as required by applicable law
  • We maintain an incident response plan and regularly review it

To report a security vulnerability or suspected incident, please contact support@oliveops.ca or see our Responsible Disclosure policy.

13. Employee and Administrator Access

OliveOps employees who require access to customer data for support or maintenance purposes are subject to:

  • Confidentiality agreements
  • Background checks
  • Principle of least privilege access (access only to data necessary for their role)
  • Audit logging of all access
  • Regular security training

14. Customer Security Responsibilities

To maintain security, customers should:

  • Use strong, unique passwords and change them regularly
  • Enable multi-factor authentication where available
  • Protect login credentials and do not share them
  • Regularly review user access and remove users who no longer need access
  • Monitor account activity and report suspicious behavior immediately
  • Comply with your own security policies and data classification standards
  • Implement appropriate business processes to protect sensitive customer data
  • Ensure employees understand and follow your organization's security practices

15. Reporting Security Issues

If you discover a security vulnerability in OliveOps, please report it responsibly to support@oliveops.ca. Do not publicly disclose the vulnerability until we have had an opportunity to assess and remediate it.

See our Responsible Disclosure policy for detailed reporting guidelines and safe-harbour protections.

16. Certifications

OliveOps does not represent that it holds any independent security certification unless explicitly stated on this website. For compliance questions or to request information about our security practices, contact support@oliveops.ca.

17. Security Limitations

No system is completely secure. Despite our best efforts, security risks cannot be entirely eliminated:

  • Vulnerabilities may be discovered in software, dependencies, or infrastructure
  • Human error or insider threats may occur
  • Zero-day vulnerabilities may be exploited before we are aware of them
  • Network or communication channels may be compromised
  • Data breaches may occur despite security precautions

We implement security controls to minimize risk, but we cannot guarantee that unauthorized access, data loss, or unauthorized disclosure will not occur. You accept these risks by using OliveOps.

For guidance on your organization's compliance obligations and risk management, consult with qualified security and legal professionals.

Questions about this policy?

Contact us with any concerns or questions about this policy.