Legal

Security

OllyGarden, Inc. | Last Updated: September 25, 2026

How we protect customer data

  • • OllyGarden, Inc. has completed a SOC 2® Type II examination covering security, availability, and confidentiality. Customers and prospects can request the report under NDA.
  • • The platform runs in Google Cloud in the EU (Netherlands) by default.
  • • Data is encrypted in transit with TLS and at rest, and telemetry samples are encrypted with a separate key for each organization.
  • • Production access is disabled by default, granted just in time, and protected by multi-factor authentication.
  • • We run penetration tests at least once a year.

Our Data Protection Policy describes these controls in detail, and our subprocessor list names every third party that processes customer data. For security questionnaires, email [email protected].

Reporting a vulnerability

If you believe you have found a security vulnerability in ollygarden.com, ollygarden.app, our APIs, or our open source projects, email [email protected]. Include the affected URL or component, the steps to reproduce the issue, and its impact as you understand it.

When you report in good faith, we will:

  • • Acknowledge your report within 3 business days
  • • Keep you informed while we investigate and fix the issue
  • • Credit you once the issue is fixed, if you wish
  • • Not pursue legal action for research that follows this policy

Please:

  • • Only access data that you own, or the minimum needed to show the issue
  • • Give us reasonable time to fix the issue before disclosing it publicly
  • • Not run denial-of-service tests, social engineering, spam, or physical attacks
  • • Not degrade the service for other customers

We do not currently run a paid bug bounty program.