← Trust Center

Security

How Optivance protects customer data — encryption, access control, infrastructure, monitoring, and incident response.

Last updated: 30 June 2026

Security overview

Security is foundational to how Optivance is built and operated. We apply layered, defence-in-depth controls across our application, infrastructure, and processes so customer data is protected at every stage. The measures below reflect our standard production environment; specific commitments are set out in our Terms of Service and Data Processing Agreement.

Customer data protection

We process customer data only to provide and improve the service, under your instructions and in line with the UK GDPR. We follow the principles of data minimisation and least privilege: we collect only what is needed, and access is restricted to personnel who require it for their role.

Encryption in transit (TLS 1.3)

All data transmitted between your devices and our service is encrypted in transit using TLS 1.3, with secure fallback to TLS 1.2 only where a client does not support 1.3. Legacy protocols and weak cipher suites are disabled.

Encryption at rest (AES-256)

Data at rest is encrypted using AES-256. Encryption keys are managed through Google Cloud Key Management Service (KMS), with access tightly controlled and logged.

Authentication

Access to accounts is protected by secure authentication. Sessions are time-limited and can be revoked at any time. We support modern authentication standards and, for organisations, centralised identity management.

Multi-factor authentication (MFA)

MFA is available to all users and can be enforced across an entire organisation, adding a second factor beyond the password to reduce the risk of account takeover.

Role-based access control (RBAC)

Permissions are governed by role-based access control. Administrators assign least-privilege roles so each team member has access only to what they need.

Secure password storage

Passwords are never stored in plain text. They are hashed using bcrypt with a unique per-user salt, and we screen new passwords against known-breached credential datasets.

API security

Our API uses authenticated, scoped keys over encrypted connections. Keys can be rotated and revoked individually. We apply rate limiting and strict input validation to protect against abuse and common API attacks.

Infrastructure security

Optivance runs on Google Cloud Platform, which provides extensive, independently audited physical and environmental security. Production environments are isolated, hardened, and access-controlled.

Network security

Production systems run within private networks with restricted ingress and egress, limited to required ports and protocols. Administrative access requires authenticated, audited channels.

Web Application Firewall (WAF)

A Web Application Firewall and Google Cloud edge protections help detect and block common web attacks — such as injection and cross-site scripting — before they reach the application.

DDoS protection

We rely on Google Cloud's global edge network to absorb and mitigate distributed denial-of-service attacks and maintain availability during volumetric events.

Audit logs

Key actions are recorded in audit logs to support accountability, investigation, and customer compliance needs. Audit log access and export are available to customers.

Monitoring

We continuously monitor availability, performance, and security signals, with automated alerting that routes anomalies to our on-call engineers.

Vulnerability management

We track and remediate vulnerabilities on a risk-prioritised basis, keeping dependencies and systems patched. Security testing is built into our development process, and we engage independent penetration testers on at least an annual basis.

Secure development lifecycle

Security is built into how we ship: peer code review, automated dependency and secret scanning, automated testing, and separation of duties between development and production.

Backup & disaster recovery

Encrypted backups run automatically every day with a 35-day retention window, stored separately from production. Our disaster recovery process targets a Recovery Point Objective of 24 hours and a Recovery Time Objective of 4 hours.

Incident response

We maintain a documented incident response plan covering detection, triage, containment, eradication, recovery, and post-incident review. Where a personal data breach occurs, affected customers are notified without undue delay and the ICO is notified within 72 hours where the breach meets the reporting threshold.

Questions about this? Contact our security & privacy team.

Contact us