Skip to content
Octopus Core

Security & Trust

Security, privacy and evidence — stated honestly

We describe our architecture and controls with honest status labels. We do not claim certifications we do not hold. Where a control is in progress or planned, we say so.

What we can say

The architecture is designed to support regulated environments; controls are mapped against relevant frameworks; certification readiness is under development; and specific requirements are assessed per engagement.

Controls

Security & privacy controls

  • Identity & access

    Authenticated access with role-based permissions and least-privilege defaults.

    Implemented
  • Encryption

    Encryption in transit; encryption at rest depending on the deployment target.

    Implemented
  • Model-provider controls

    Central gateway so model access passes through policy, with provider routing controls.

    Implemented
  • Logging & evidence

    Action and decision logging designed to produce inspectable, audit-ready records.

    In progress
  • Human approval

    Approval boundaries for high-impact actions, configurable per policy.

    Implemented
  • Data residency

    Residency-aware routing available by configuration; Australian-region options assessed per engagement.

    Supported
  • Sensitive-data controls

    Detection and redaction controls across the AI path.

    In progress
  • Business continuity

    Backup and recovery practices assessed per deployment.

    In progress
  • Secure development

    Reviewable changes, version control and testing as standard practice.

    Implemented
  • Responsible disclosure

    A channel for reporting security issues (see the disclosure page).

    Implemented

Frameworks

Compliance mappings & readiness

ISO/IEC 27001

In progress

Controls mapped; certification readiness under development. Not certified.

ISO/IEC 42001

Planned

AI management-system alignment on the roadmap. Not certified.

SOC 2

Planned

Under consideration; not assessed. Not compliant claim made.

Australian regulated environments

In progress

Architecture designed to support regulated deployments; requirements assessed per engagement.

These are mappings and readiness statuses — not certifications. We do not claim to be certified against any framework unless verified documentation exists.

Documents

Trust documents

Placeholders for materials in preparation. They will be published when ready.

  • Security whitepaperIn progress
  • Data processing addendum (DPA)Planned
  • Subprocessor listPlanned
  • Status pagePlanned

Discuss your architecture with us