OTP is pre-SOC 2 and targeting SOC 2 Type II within six months. We document our controls openly here rather than hide behind a badge we have not yet earned. Our infrastructure runs on Railway, which is SOC 2 Type II certified and HIPAA compliant.
Last updated July 26, 2026
Private by default. Your operational data is scoped to your organization and is never exposed on any cross-org surface unless you take an explicit action to publish it.
Each of these requires an explicit action by you.
Organizations flagged private are hard-excluded from every cross-org surface — browse, search, the intelligence graph, recommendations, published best-practices listings, and the network API — regardless of any per-item publish setting.
Enforced through a single shared control so the rule cannot drift between surfaces. A boot-time check rebuilds the network data view to include the same exclusion.
Privacy is all-or-nothing at the organization level; there is no per-item private override.
Multi-tenant by design. Every record (priorities, to-dos, KPIs, meetings, org chart, learnings) carries an organization ID, and every request is bound to one organization before any data is read.
Tenant scoping is enforced in the application layer on every route, and every cross-org read additionally passes through one shared visibility control. We disclose plainly that isolation is enforced in the application, not via database row-level security.
We are an early-stage protocol. We tell you exactly where we are.
On confirming a security incident affecting customer data, we contain it and notify affected organizations within 3 hours, followed by a written post-incident summary.
No reportable security incidents to date.
A comprehensive security audit was completed in July 2026, covering authentication, multi-tenant isolation, injection, the dependency supply chain, and file handling. Findings were remediated and verified in production, and the production dependency tree carries no known high or critical vulnerabilities; any remaining advisories are low or moderate and tracked to resolution. This was a code-level internal review, not a third-party penetration test — a formal external assessment is planned as we grow.
See what was hardened & live status →By default, nothing. Your operating data stays private to your organization. Only items you explicitly publish (learnings, selected best practices, or a profile or KPIs you mark public) appear on the network.
No. Those are private to your organization and never appear on any cross-org surface.
Yes. A private organization is hard-excluded from every cross-org surface through a single enforced control.
In the EU, in Railway's Amsterdam region, encrypted at rest, with daily encrypted backups retained 30 days.
No. AI features send only the content needed for that request to Anthropic's Claude API to generate your response, and Anthropic does not train on data submitted through its paid API.
Yes. On a verified deletion request, personal data is permanently removed within 7 days. You can request a copy of your data, and a self-serve export is on the roadmap.
OTP records an aggregate daily count of the changes each member makes, so an organization's leadership can see which days a person was active and roughly how much they did. It does not capture IP addresses, devices, pages viewed, or the content of any action. These numbers are visible only inside your own organization, to leadership roles, and to OTP platform administrators in aggregate.
Yes. Every member has a personal data page (Settings, My data) showing their identity record, what the organization holds that involves them, and who has viewed their meeting transcripts. This is a product surface, not a support request.
Challenge it. Any member can contest an Ollie Insight, or one specific receipt it cites, right where it appears. The challenge stays attached to the insight, anyone can respond, and only the person who raised it can close it. A wrong claim cannot be quietly outranked or regenerated away.
We are pre-SOC 2 and targeting SOC 2 Type II within six months; our infrastructure already runs on SOC 2 Type II, HIPAA-compliant Railway. For GDPR, customer data is hosted in the EU and a DPA is available on request.
We respond to security inquiries within 1 business day. Our Data Processing Agreement is available on request.
security@orgtp.com
OrgTP, LLC · Fairfield, NJ 07004, USA