OptiTech's Security & Compliance
At OptiTech, security, compliance, privacy, and transparency are core to our platform. We protect customer data through industry leading security controls, independent audits, and strict adherence to global compliance standards.
Compliance Frameworks

SOC 2 Type II
OptiTech undergoes annual SOC 2 Type II audits performed by accredited independent third party auditors. The SOC 3 report, a public summary of our SOC 2 compliance, is available without an NDA in the Trust Center.

ISO/IEC 27001:2022 & ISO/IEC 27701:2019
OptiTech undergoes annual ISO/IEC 27001:2022 and ISO/IEC 27701:2019 audits for its security and privacy management systems. These certifications validate our commitment to global standards.
Privacy & Regulations

California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
OptiTech complies with CCPA and CPRA, ensuring data privacy and transparency. We don't sell, share, or retain personal data beyond contractual obligations, allowing users to manage their preferences.

European General Data Protection Regulation (GDPR)
OptiTech follows the GDPR framework, ensuring user rights, data minimization, and lawful processing. We offer Data Processing Agreements (DPA) and support compliant cross-border data transfers.
United States Health Insurance Portability and Accountability Act of 1996 (HIPAA)
OptiTech has achieved HIPAA compliance to support customers handling protected health information (PHI). Our security measures include encryption of electronic PHI, least-privilege access control, security monitoring for unauthorized data access, and comprehensive audit logging.

Trust Center
Request audit reports, certifications, and compliance documentation via our Trust Center.
For additional security inquiries, contact security@optitech.com.
OptiTech Compliance Platform
Secure, cloud-hosted compliance automation for Nordic SMBs and their supply chains.
Cloud Infrastructure
Hosted on AWS and Azure, leveraging built-in security controls.
Data Storage & Processing
Encryption, access controls, and secure data retention policies.
Access & Security Controls
Identity management, monitoring, and compliance enforcement.
Personnel Security
Employee background checks, security training, and access management.
Sub-Processors
OptiTech engages with carefully selected third-party sub-processors that assist in service delivery.
All sub-processors are reviewed annually and must comply with contractual security and privacy requirements. A list of our third-party sub-processors is available on our website.

Features
Still have questions? Ask our AI.
It knows OptiTech inside and out.
