Legal
Security
OllyGarden, Inc. | Last Updated: September 25, 2026
How we protect customer data
- • OllyGarden, Inc. has completed a SOC 2® Type II examination covering security, availability, and confidentiality. Customers and prospects can request the report under NDA.
- • The platform runs in Google Cloud in the EU (Netherlands) by default.
- • Data is encrypted in transit with TLS and at rest, and telemetry samples are encrypted with a separate key for each organization.
- • Production access is disabled by default, granted just in time, and protected by multi-factor authentication.
- • We run penetration tests at least once a year.
Our Data Protection Policy describes these controls in detail, and our subprocessor list names every third party that processes customer data. For security questionnaires, email [email protected].
Reporting a vulnerability
If you believe you have found a security vulnerability in ollygarden.com, ollygarden.app, our APIs, or our open source projects, email [email protected]. Include the affected URL or component, the steps to reproduce the issue, and its impact as you understand it.
When you report in good faith, we will:
- • Acknowledge your report within 3 business days
- • Keep you informed while we investigate and fix the issue
- • Credit you once the issue is fixed, if you wish
- • Not pursue legal action for research that follows this policy
Please:
- • Only access data that you own, or the minimum needed to show the issue
- • Give us reasonable time to fix the issue before disclosing it publicly
- • Not run denial-of-service tests, social engineering, spam, or physical attacks
- • Not degrade the service for other customers
We do not currently run a paid bug bounty program.