For a comprehensive overview, please visit our Trust center.
At Ovida, privacy and data protection are not add-ons - they are core to our platform’s design. From the very beginning, Ovida has been architected with security as a foundational principle.
Our practices have been independently validated through a SOC 2 Type 1 report, confirming our commitment to enterprise-grade security.
Key Security and Privacy controls
Here are the measures we put in place to keep your data safe:
1. Validated security controls
- We run regular vulnerability scans to identify and address potential risks. 
- Penetration tests are conducted to simulate attacks and ensure resilience. 
- Intrusion detection systems monitor our platform for suspicious activity. 
2. Data encryption
- All customer data is encrypted at rest (when stored). 
- All customer data is encrypted in transit (when sent or received). 
3. World-Class Infrastructure
- Ovida is hosted on Amazon Web Services (AWS), leveraging its industry-leading reliability and security standards. 
4. Strict Access Management
- We enforce role-based access controls to ensure users only have access to what they need. 
- The Principle of Least Privilege governs all system access, minimizing potential risk. 
5. Formal Incident Response
- We maintain a documented incident response plan so our team can act quickly and effectively in the unlikely event of a security issue. 
6. Data Management & Deletion
- You are always in control of your data. 
- Users have the absolute right to permanently delete their data at any time. 
