← Trust Center

Security Policy

Optivance's public security policy, including how we protect data and handle incidents.

Last updated: 30 June 2026

Effective date: 30 June 2026

This Security Policy summarises the security commitments of Optivance Ltd. Detailed controls are described on our Security and Infrastructure pages.

Scope

This policy covers the Optivance production service and the customer data processed within it.

Our commitments

  • Encrypt data in transit (TLS 1.3) and at rest (AES-256), with keys managed in Google Cloud KMS.
  • Apply least-privilege access control and enforce MFA for administrative access.
  • Maintain continuous monitoring, logging, and alerting across production systems.
  • Manage vulnerabilities on a risk-prioritised basis and keep systems patched.
  • Build security into our development lifecycle through review, scanning, and testing.
  • Maintain encrypted daily backups and a tested disaster recovery capability.

Incident response

We maintain a documented incident response plan. We notify affected customers without undue delay and, where a personal data breach meets the threshold, notify the ICO within 72 hours of becoming aware.

Personnel

Staff receive security awareness training and are bound by confidentiality obligations. Access is granted on a need-to-know basis and removed promptly on role changes.

Reporting a concern

Report security concerns or vulnerabilities under our Responsible Disclosure Policy, or email security@optivance.co.uk.

Questions about this? Contact our security & privacy team.

Contact us