Security Policy
Optivance's public security policy, including how we protect data and handle incidents.
Last updated: 30 June 2026
Effective date: 30 June 2026
This Security Policy summarises the security commitments of Optivance Ltd. Detailed controls are described on our Security and Infrastructure pages.
Scope
This policy covers the Optivance production service and the customer data processed within it.
Our commitments
- Encrypt data in transit (TLS 1.3) and at rest (AES-256), with keys managed in Google Cloud KMS.
- Apply least-privilege access control and enforce MFA for administrative access.
- Maintain continuous monitoring, logging, and alerting across production systems.
- Manage vulnerabilities on a risk-prioritised basis and keep systems patched.
- Build security into our development lifecycle through review, scanning, and testing.
- Maintain encrypted daily backups and a tested disaster recovery capability.
Incident response
We maintain a documented incident response plan. We notify affected customers without undue delay and, where a personal data breach meets the threshold, notify the ICO within 72 hours of becoming aware.
Personnel
Staff receive security awareness training and are bound by confidentiality obligations. Access is granted on a need-to-know basis and removed promptly on role changes.
Reporting a concern
Report security concerns or vulnerabilities under our Responsible Disclosure Policy, or email security@optivance.co.uk.
Questions about this? Contact our security & privacy team.
Contact us