Template pending legal review. This document is a working draft prepared by Octenta and has not yet been reviewed or approved by legal counsel.

Trust

Security at Octenta

Last updated: 1 July 2026

The controls that govern how Octenta AI Employees access data, what they are permitted to execute, and how every decision is recorded.

1. Our approach

Octenta deploys AI Employees into systems that hold a company's most sensitive operational data. The platform is therefore built so that capability is granted deliberately, exercised within explicit boundaries, and recorded in full. This page describes the controls Octenta operates. It is maintained by Octenta and is not an independent audit report or certification.

2. Deployment controls: Shadow Mode

Every AI Employee starts in Shadow Mode. It reads live data and reaches a decision on every item, but writes nothing back to a connected system. Execution permission is granted category by category by a customer administrator, and any category can be returned to Shadow Mode instantly.

Permission boundaries are enforced by the platform, not by model behaviour. A decision outside a granted category is held for human approval regardless of the confidence attached to it.

3. Access control

  • Role-based access control across all platform functions, administered by the customer.
  • Least-privilege integration scopes: each connected system is granted only the permissions the deployed role requires.
  • Support for single sign-on and enforced multi-factor authentication where the customer's identity provider supports it.
  • Octenta personnel access to customer environments is limited, purpose-bound, time-bound and logged.

4. Encryption

Data is encrypted in transit using current TLS standards and encrypted at rest using industry-standard algorithms. Credentials and integration secrets are stored in a managed secrets service and are never exposed in application logs or the user interface.

5. Audit logging

Every decision an AI Employee reaches is written to an append-only log recording the timestamp, the employee, the source records read, the decision, the confidence, whether it executed or was held, and the identity of the human who approved, amended or rejected it.

Log entries cannot be edited or deleted, including by administrators. Corrections are appended as new entries referencing the original, so the history of any decision can be reconstructed in full.

6. Infrastructure and availability

  • Hosting with established cloud providers operating physically secured, certified data centres.
  • Environment separation between development, staging and production.
  • Encrypted, monitored backups with tested restore procedures.
  • Continuous monitoring and alerting on availability, error rates and anomalous access patterns.

7. Secure development

  • Peer review required for all changes to production code.
  • Automated dependency and vulnerability scanning in the build pipeline.
  • Static analysis and secret detection before deployment.
  • Periodic penetration testing by qualified third parties, with findings tracked to resolution.

8. Data handling

Customer business data is used only to deliver the contracted service. Octenta does not use customer business data to train general-purpose models for other customers. Data residency and retention are configured according to the customer agreement, and data is exportable and deletable at the end of the term.

9. Compliance posture

Octenta aligns its control set with recognised frameworks including SOC 2 criteria and GDPR requirements, and supports customers with data-processing terms and subprocessor disclosure. Where a certification or attestation report is required for procurement, contact Octenta and we will confirm current status and provide the relevant documentation directly rather than asserting it here.

10. Incident response

Octenta maintains a documented incident-response process covering detection, triage, containment, remediation and post-incident review. Affected customers are notified in line with contractual and legal timeframes, with the facts established and the audit trail available.

11. Reporting a vulnerability

If you believe you have found a security vulnerability in an Octenta product or in octenta.com, contact us through the contact page and mark your message for the attention of the security team. Please include enough detail to reproduce the issue. We investigate every report and will not pursue action against good-faith research that avoids privacy violations and service disruption.

Questions about this document?

Contact the Octenta team and we will route your question to the right person.

Contact Octenta