What security compliance certifications and standards does Olakai meet?

Olakai has completed an independent SOC 2 Type II examination, covering the report period March 1 to May 31, 2026 against the Security Trust Services Criteria. The report is available under NDA. Payment processing runs exclusively through Stripe, which is PCI DSS Level 1, and Olakai does not store payment card data. All core infrastructure vendors maintain SOC 2 Type II or equivalent certifications.

SOC 2 Type II

Olakai maintains rigorous security practices across all infrastructure and operations, backed by an independent SOC 2 Type II examination.

The Trust page states the scope rather than leaving it to inference. The examination is complete, the report period is March 1 to May 31, 2026, and the Trust Services Criteria covered is Security. The report itself is available under NDA.

Source: Trust & Security

Vendor coverage

All core infrastructure vendors, namely AWS, Stripe, GitHub, Okta, Sentry and Upstash, maintain SOC 2 Type II or equivalent certifications.

The Trust page names what each is held to. AWS provides hosting, database, storage and CDN, and is listed as SOC 2 Type II, ISO 27001 and FedRAMP. Stripe handles billing and payments at PCI DSS Level 1. Okta provides enterprise SSO, listed as SOC 2 Type II and ISO 27001. Upstash provides API rate limiting at SOC 2 Type II. GitHub provides the code repository and PR analytics at SOC 2 Type II, and Sentry provides error monitoring at SOC 2 Type II.

AI providers are treated separately. Anthropic, OpenAI, Google Cloud AI, Mistral and Perplexity are API-only, with minimal retention and no persistent data storage.

Source: Trust & Security

PCI DSS and payment data

Payment processing is handled exclusively by Stripe, which is PCI DSS Level 1. Olakai does not store payment card data.

Source: Trust & Security

Hosting and infrastructure

Olakai is hosted entirely on Amazon Web Services in the us-east-1 region, using isolated private networking throughout.

  • Compute: containerized Next.js applications on AWS ECS Fargate with auto-scaling, 2 to 6 instances based on CPU and memory thresholds.
  • Database: Amazon RDS PostgreSQL 16 in a private subnet with no direct internet access, Multi-AZ enabled in production for high availability.
  • Storage: Amazon S3 with server-side encryption for all document storage.
  • CDN: Amazon CloudFront for static asset and document delivery.
  • Network: VPC with public and private subnet isolation. Database and application containers reside in private subnets, accessible only via internal routing.

Source: Trust & Security

Encryption

All data is encrypted in transit and at rest using industry-standard algorithms.

In transit, TLS 1.2+ is used on all external connections, with HTTPS enforced on all endpoints and HTTP 80 redirecting to 443. At rest, AES-256 is applied via AWS RDS for the database and AWS S3 for file storage, with AES-256-GCM for sensitive application fields. Sessions use HMAC-SHA256 signed JWTs in HTTP-only, Secure, SameSite cookies, and passwords are stored using bcrypt one-way hashing.

Source: Trust & Security

Access control and multi-tenant isolation

Olakai uses Role-Based Access Control with strict multi-tenant isolation enforced at every layer.

Every database query is scoped by accountId. No customer can access another customer's data, and this is enforced at the application layer across all repositories, use cases and server actions, supplemented by automated tests and query guards.

Customer roles are USER for own data only, ANALYST for account-wide read access to analytics and dashboards, and ADMIN for full account management covering users, billing and configuration. Enterprise provisioning uses SCIM 2.0 with bearer token authentication. Olakai staff use a separate MFA-protected console, where support sessions grant time-limited four-hour access via single-use tokens, fully audited with initiator identity, target account and IP address.

Source: Trust & Security

Data privacy

Customer data is never shared across tenants, and AI providers process data via API only, with no persistent storage at the provider level.

Prompt Privacy Mode is an optional per-account setting requiring explicit authorization for non-admin users to view prompt content, and all access attempts are audit-logged. Admins can define and enforce Acceptable Use Policies that users must accept before using monitored AI applications, and acceptance records are permanently retained.

Source: Trust & Security

Security testing

Olakai maintains a layered security testing program combining automated scanning with manual penetration testing.

Dependabot is enabled across all repositories, continuously monitoring for known vulnerabilities, with security advisories triggering automated PRs reviewed and merged on a priority basis. Regular internal assessments cover the OWASP Top 10, authentication and authorization flows, multi-tenant isolation and API security. Independent penetration testing by qualified external security firms runs on a periodic basis, covering web application, APIs and infrastructure.

Source: Trust & Security

Getting the documentation

Olakai is designed to meet the security and compliance requirements of enterprise organizations. The Trust page documents the infrastructure, controls and practices so security and procurement teams have what they need. For NDA-protected documentation, pen test summaries, or to discuss specific requirements, the page directs you to contact the team.

Source: Trust & Security

Also asked as

  • What security certifications and compliance standards does Olakai hold?
  • Is Olakai SOC 2 Type II and PCI DSS compliant?
  • How does Olakai handle enterprise compliance and data protection standards?

Related questions

← All answers