# Security

Legal

# Security

OllyGarden, Inc. | Last Updated: September 25, 2026

## How we protect customer data

- • OllyGarden, Inc. has completed a SOC 2® Type II examination covering security, availability, and confidentiality. Customers and prospects can request the report under NDA.
- • The platform runs in Google Cloud in the EU (Netherlands) by default.
- • Data is encrypted in transit with TLS and at rest, and telemetry samples are encrypted with a separate key for each organization.
- • Production access is disabled by default, granted just in time, and protected by multi-factor authentication.
- • We run penetration tests at least once a year.Our [Data Protection Policy](/data-protection-policy) describes these controls in detail, and our [subprocessor list](/subprocessors) names every third party that processes customer data. For security questionnaires, email [[email protected]](/cdn-cgi/l/email-protection#4635232533342f323f06292a2a3f2127342223286825292b).

## Reporting a vulnerability

If you believe you have found a security vulnerability in ollygarden.com, ollygarden.app, our APIs, or our open source projects, email [[email protected]](/cdn-cgi/l/email-protection#1261777167607b666b527d7e7e6b75736076777c3c717d7f). Include the affected URL or component, the steps to reproduce the issue, and its impact as you understand it.

When you report in good faith, we will:

- • Acknowledge your report within 3 business days
- • Keep you informed while we investigate and fix the issue
- • Credit you once the issue is fixed, if you wish
- • Not pursue legal action for research that follows this policyPlease:

- • Only access data that you own, or the minimum needed to show the issue
- • Give us reasonable time to fix the issue before disclosing it publicly
- • Not run denial-of-service tests, social engineering, spam, or physical attacks
- • Not degrade the service for other customersWe do not currently run a paid bug bounty program.

Canonical URL: https://ollygarden.com/security