OffDeck/Security

Security at OffDeck.

The things your team writes inside OffDeck — anonymous pulses, reflections, growth plans — are exactly the things that have to stay safe. Here's how we do that, in detail.

SOC 2 Type II · AICPA TLS 1.3 & AES-256 at rest SSO & SCIM on every plan EU residency on Studio Penetration tests annually

Six pillars, plainly written.

Each pillar links to the technical detail behind it. For deeper conversations — vendor reviews, BAAs, security questionnaires — write to [email protected].

Application security

The product itself, audited and tested.

  • SOC 2 Type II — report available under NDA.
  • Annual penetration testing by an independent firm.
  • SAST & DAST on every deploy — we don't ship known CVEs.
  • Bug bounty via HackerOne, scope on the VDP page.

Encryption

Strong, modern, no exceptions.

  • In transit — TLS 1.3 (TLS 1.2 minimum), HSTS preload.
  • At rest — AES-256 (FIPS-140 validated) on all data stores.
  • Field-level — pulse and reflection bodies double-encrypted with per-tenant keys.
  • Key management — AWS KMS with quarterly rotation.

Access control

Least privilege, every layer.

  • SSO & SCIM on every plan — Okta, Microsoft, Google.
  • 2FA mandatory for OffDeck employees with any production access.
  • Just-in-time production access; logged, time-bound, peer-approved.
  • Customer-side roles — admin, manager, member, viewer. Granular.

Data residency

Pick where your data lives.

  • US (us-east-1, Northern Virginia) — default.
  • EU (eu-west-1, Ireland) — Studio plan.
  • Backups in the same region as primary, never cross-region.
  • No data is sent outside your chosen region without your explicit instruction.

Operational security

How we run the company.

  • Background checks for every hire (where lawful).
  • Annual security training with quarterly phishing simulations.
  • Incident response — documented, drilled, with defined RTO/RPO targets.
  • Vendor reviews annually for every sub-processor.

Privacy by design

The product itself, shaped to protect.

  • Anonymous pulses — suppressed below n=4. Math can't be reverse-engineered.
  • No training — your data never trains a third-party AI model.
  • Customer-side export & delete — one click, any time.
  • Minimum-necessary retention — see the privacy policy.

Sub-processors.

The third-party services we rely on. Each is bound by a Data Processing Agreement and reviewed annually. We notify customers at least 30 days before adding or changing a sub-processor — subscribe to updates.

Sub-processorPurposeLocationSOC 2 / equivalent
Amazon Web ServicesHosting, storage, backupUS · EUYes
StripePayment processingUSPCI DSS Level 1
PostmarkTransactional emailUSYes
SentryError monitoring (anonymised)USYes
WorkOSSingle sign-on & SCIMUSYes
PlausiblePrivacy-friendly analyticsEU (Germany)GDPR compliant
AnthropicDrafting assistance (opt-in, anonymised)USYes

If something happens.

If we believe your data has been improperly accessed, we'll tell you — in writing, within 72 hours of confirmation, with what we know and what we're doing about it. We will not bury bad news in a status page. We have never had a reportable data breach.

Live status: status.html. Historical incidents are kept on file and available to customers under NDA.

Reporting a vulnerability.

Found something? Thank you. Email [email protected] with reproduction steps. We respond within 24 hours, validate within five business days, and credit you on our hall-of-fame unless you'd rather we didn't. We offer bounties via HackerOne for in-scope issues; the scope and reward bands live in the program description.

For PGP-encrypted reports, our public key fingerprint is 9A3C 4F71 38E2 B5C1 4D9E 2A8B 6F03 D5C4 7E1F 8B12.

Security questionnaire? DPA? Pen-test report?

We respond to every security review the same week. We've answered SIG, CAIQ, and our customers' bespoke questionnaires. If your procurement team needs something specific — even before a contract is in motion — just ask.

Security contact
Avg. response · under 4 hours, business days
Critical reports: under 1 hour, 24/7