Security at OffDeck.
The things your team writes inside OffDeck — anonymous pulses, reflections, growth plans — are exactly the things that have to stay safe. Here's how we do that, in detail.
Six pillars, plainly written.
Each pillar links to the technical detail behind it. For deeper conversations — vendor reviews, BAAs, security questionnaires — write to [email protected].
Application security
The product itself, audited and tested.
- SOC 2 Type II — report available under NDA.
- Annual penetration testing by an independent firm.
- SAST & DAST on every deploy — we don't ship known CVEs.
- Bug bounty via HackerOne, scope on the VDP page.
Encryption
Strong, modern, no exceptions.
- In transit — TLS 1.3 (TLS 1.2 minimum), HSTS preload.
- At rest — AES-256 (FIPS-140 validated) on all data stores.
- Field-level — pulse and reflection bodies double-encrypted with per-tenant keys.
- Key management — AWS KMS with quarterly rotation.
Access control
Least privilege, every layer.
- SSO & SCIM on every plan — Okta, Microsoft, Google.
- 2FA mandatory for OffDeck employees with any production access.
- Just-in-time production access; logged, time-bound, peer-approved.
- Customer-side roles — admin, manager, member, viewer. Granular.
Data residency
Pick where your data lives.
- US (us-east-1, Northern Virginia) — default.
- EU (eu-west-1, Ireland) — Studio plan.
- Backups in the same region as primary, never cross-region.
- No data is sent outside your chosen region without your explicit instruction.
Operational security
How we run the company.
- Background checks for every hire (where lawful).
- Annual security training with quarterly phishing simulations.
- Incident response — documented, drilled, with defined RTO/RPO targets.
- Vendor reviews annually for every sub-processor.
Privacy by design
The product itself, shaped to protect.
- Anonymous pulses — suppressed below n=4. Math can't be reverse-engineered.
- No training — your data never trains a third-party AI model.
- Customer-side export & delete — one click, any time.
- Minimum-necessary retention — see the privacy policy.
Sub-processors.
The third-party services we rely on. Each is bound by a Data Processing Agreement and reviewed annually. We notify customers at least 30 days before adding or changing a sub-processor — subscribe to updates.
| Sub-processor | Purpose | Location | SOC 2 / equivalent |
|---|---|---|---|
| Amazon Web Services | Hosting, storage, backup | US · EU | Yes |
| Stripe | Payment processing | US | PCI DSS Level 1 |
| Postmark | Transactional email | US | Yes |
| Sentry | Error monitoring (anonymised) | US | Yes |
| WorkOS | Single sign-on & SCIM | US | Yes |
| Plausible | Privacy-friendly analytics | EU (Germany) | GDPR compliant |
| Anthropic | Drafting assistance (opt-in, anonymised) | US | Yes |
If something happens.
If we believe your data has been improperly accessed, we'll tell you — in writing, within 72 hours of confirmation, with what we know and what we're doing about it. We will not bury bad news in a status page. We have never had a reportable data breach.
Live status: status.html. Historical incidents are kept on file and available to customers under NDA.
Reporting a vulnerability.
Found something? Thank you. Email [email protected] with reproduction steps. We respond within 24 hours, validate within five business days, and credit you on our hall-of-fame unless you'd rather we didn't. We offer bounties via HackerOne for in-scope issues; the scope and reward bands live in the program description.
For PGP-encrypted reports, our public key fingerprint is 9A3C 4F71 38E2 B5C1 4D9E 2A8B 6F03 D5C4 7E1F 8B12.
Security questionnaire? DPA? Pen-test report?
We respond to every security review the same week. We've answered SIG, CAIQ, and our customers' bespoke questionnaires. If your procurement team needs something specific — even before a contract is in motion — just ask.