Security & compliance

Built for the controls enterprise procurement looks for.

OizyOS is engineered against ISO 27001 and SOC 2 Type II from the architecture up — multi-tenant isolation at the database layer, immutable audit logging, posture-gated privileged actions, PII encryption at rest. The current state of every control is below, with file paths so you can verify in the source.

ISO 27001 alignment
Architected for; not yet certified

Every phase of the platform is built against the ISO 27001 control set. Stage 1 audit-readiness is the next compliance milestone — we maintain control evidence per area below and welcome external review of any control.

SOC 2 Type II alignment
Architected for; observation period not yet started

Controls map to the SOC 2 Trust Services Criteria (CC6, CC7, C1, AP2). When a customer engagement requires SOC 2 Type II, we can begin a formal observation period without architectural change.

GDPR / Privacy Act
Built in by design

Data minimisation, retention limits, right-to-erasure flows, and tenant-controlled data export are first-class controls. PII scrubbing applies to logs, LLM context, and exports.

Control areas

Each control area below names the ISO and SOC criteria it maps to, the implementation approach, and the file paths in the codebase that serve as evidence. Welcome to verify any of them under NDA.

Access control

ISO A.9SOC CC6

Role-based access control with eight tiers (agent → super_admin). Every API route is authenticated via a centralised `withAuth` wrapper that enforces session, role, and security posture before any handler runs.

src/lib/auth/api-auth.ts

Multi-tenant isolation

ISO A.13SOC CC6.1

Tenants are isolated at the database level via Postgres Row Level Security. Tenant context is resolved from subdomain in middleware before the request reaches any handler. Cross-tenant queries are not possible without explicit service-role escalation.

src/middleware.ts, src/lib/tenant/resolve.ts

Audit trail

ISO A.12.4SOC CC7

Every mutating action writes to an immutable audit log: actor, action, entity, timestamp, IP address, request ID. Audit-write failures halt the operation rather than continuing silently. PII patterns (email, phone, ID) are scrubbed from log output before serialisation.

src/core/audit/logger.ts

Secrets and key management

ISO A.10SOC C1

Application secrets live in environment variables and the encrypted `connector_configs` table. Service-role keys are isolated to server-side code paths and never exposed to the browser. Magic-link OTP, password reset, and session JWTs are issued by the upstream identity provider (Supabase Auth).

src/lib/supabase/admin.ts, src/lib/services/connector-config.ts

Transport and headers

ISO A.10.1SOC CC6.7

TLS 1.2+ enforced everywhere. HSTS preload, Content Security Policy with origin allowlist (Supabase, Twilio, Anthropic, OpenAI), X-Frame-Options SAMEORIGIN, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy restricting camera and geolocation. CSP currently allows inline scripts/styles — migration to nonce-based CSP is planned.

netlify.toml

Input validation

ISO A.14SOC CC6.6

Every API endpoint validates request bodies with Zod schemas before reaching business logic. Database queries use parameterised statements — never string interpolation. CSV exports and imports are sanitised against formula injection.

src/core/validation/, schema files alongside each module

Posture and elevation

ISO A.9.4SOC CC6.2

Three security postures (SELF_SERVICE, TRUSTED_WORK, BUILDER) govern access to sensitive operations. Elevation to TRUSTED_WORK requires MFA-backed session tokens for sustained access. Privileged operations (PII unlock, data exports) require explicit step-up authentication with a separate token, IP allowlist, and rate-limited unlock window.

src/core/security/posture.ts, src/core/security/pii-sessions.ts

Data protection

ISO A.10SOC C1

PII columns (analyst identities, customer identifiers) are encrypted with AES-256-GCM at rest. Encryption keys are managed via Supabase Vault. Backups inherit the same encryption posture; backup restoration is verified on a schedule.

src/lib/crypto/pii-encrypt.ts

For your procurement team

We can provide the following on request, under NDA:

  • Detailed control evidence pack mapped to ISO 27001 Annex A and SOC 2 Trust Services Criteria
  • Data flow diagrams, sub-processor list, and data residency options
  • Architectural review of any specific control area, including read access to the source repository
  • Penetration test results when available, vulnerability management policy, and incident response plan
  • SAML 2.0 SSO integration documentation for your IdP (Okta, Azure AD, Google Workspace)
Back to overview