Skip to content
Octopus Core

Security

Security is central to how we build and operate Octopus Core. This page describes the security posture of this website and our general approach; controls specific to the Octoryn platform are covered in our Trust centre. This is a draft pending professional legal review and is not legal advice.

Legal pages are draft content pending review and are not a substitute for professional advice.

Our approach

This website is built with security controls such as HTTP security headers and a content security policy, server-side validation and rate limiting on forms, and least-privilege access to the systems behind it. We keep secrets out of client-side code and apply the principle of least privilege across our infrastructure. Our aim is defence in depth, so that a weakness in one layer does not compromise the whole.

How we handle your data

The only personal information this website collects from you directly is what you submit through the enquiry form, which is handled as described in our Privacy policy. Please do not submit sensitive records, credentials, health information or confidential client data through the form. If you need to share sensitive material as part of an engagement, we will agree an appropriate and secure channel with you first.

Reporting a vulnerability

We welcome reports from security researchers and users who believe they have found a vulnerability in this website or our services. Please contact us through our security contact so we can triage and respond responsibly, and we ask that you give us a reasonable opportunity to address the issue before any public disclosure. Please do not access, modify or delete data that is not your own while testing.

Shared responsibility

Security in any deployment is a shared responsibility between us and the organisations we work with. The specific controls, data-handling arrangements and safeguards appropriate to a given use case are assessed on a per-engagement basis, taking into account the requirements of your environment. We work with you to define responsibilities clearly before any regulated or production use.

Certification status

Our architecture is designed to support regulated environments, and certification readiness is under active development. We do not currently claim any formal security or compliance certification, and we will not represent ourselves as certified until such certification is formally in place. Where a specific standard is relevant to an engagement, we will discuss our current status openly.

Trust centre

For more detail on the security and governance controls that apply to the Octoryn platform, please refer to our Trust centre. It provides further information on platform architecture and controls, which is assessed and tailored per engagement. If you have questions not answered there, please reach us through our security contact.

Legal name:
Octopus Core Pty Ltd
ABN:
28 696 931 236
ACN:
696 931 236
Business location:
Sydney NSW 2007, Australia

Last verified: —