Security built into how we operate.
Protecting the data our customers trust us with is core to how we build and operate AIRA, Sentio and Canopy. This page describes our current security program and the safeguards we use to protect customer data and the Services.
Notice:It supplements our Privacy Policy and Terms & Conditions and does not replace the specific commitments in a customer's Data Processing Agreement or Customer Agreement.
100% Encrypted
In transit & at rest
Role-Based Access
Strict least-privilege
Continuous Monitoring
Proactive incident response
Zero AI Training
No customer data model training
Security Governance & Risk Management
Olive Branch maintains a risk-based security program designed to protect the confidentiality, integrity and availability of information processed through the Services. Our security practices are supported by documented policies, assigned responsibilities and controls appropriate to the nature and sensitivity of the information we process.
Risk Evaluation
Security risks are evaluated based on factors such as the nature of the information, the Services involved, the applicable use case and potential impact.
Control Prioritization
We periodically review security practices and controls and prioritize remediation of identified risks based on severity and potential impact.
Personnel Security
Personnel with access to Customer Data are subject to confidentiality obligations and security awareness requirements appropriate to their roles.
Identity & Access Management
Access to customer environments and systems is governed by strictly defined protocols and verifiable need.
Role-Based Access & Least Privilege
Access to systems handling Customer Data is governed by role-based access and the principle of least privilege and need-to-know.
Privileged Access Controls
Authentication controls are applied to customer and internal access to the Services and supporting systems, with enhanced controls for privileged access where appropriate.
Lifecycle Access Reviews
Access rights are reviewed and adjusted as appropriate when personnel change roles or leave the organization.
Infrastructure & Network Security
Olive Branch's Services are hosted on infrastructure provided by established cloud service providers. We rely on our providers' physical and environmental security controls for the data centers underlying our Services, and layer our own application-level, network-level and data-level controls on top of that infrastructure.
Established Providers
Physical and environmental data center security managed by leading cloud providers.
Layered Controls
Application-level, network-level and access controls layered above the infrastructure.
Transit & Rest
Data is encrypted in transit and at rest using security controls appropriate to the applicable systems and data.
Logical Segregation
Customer Data is logically segregated by customer account, with controls designed to reduce unauthorized cross-customer access.
Secure Development & Vulnerability Management
Security considerations are incorporated into our software development and deployment processes. Controls applied to a particular change may vary based on its nature, scope and risk.
Monitoring
We maintain vulnerability-management practices that include monitoring for relevant vulnerabilities.
Assessment
Identified vulnerabilities are assessed based on factors such as severity, exploitability, and affected systems.
Prioritization
Remediation is prioritized according to assessed risk and potential impact across systems.
Patching
Regular patching of production infrastructure to maintain operational and software integrity.
Security Testing
We conduct or commission security testing appropriate to the nature and risk of the Services.
Security Monitoring & Incident Response
Olive Branch maintains systematic incident-response procedures designed to identify, contain, investigate and remediate security incidents.
Escalation & Review
Incident response may include escalation, containment, investigation, remediation and post-incident review, as appropriate to the circumstances.
Customer Notification
We notify affected customers of a security incident in accordance with applicable contractual and legal obligations.
Testing & Exercises
We periodically review and, where appropriate, test our incident-response procedures and related escalation processes.
Business Continuity, Backup & Disaster Recovery
Olive Branch maintains resilience, backup and recovery practices appropriate to the Services and the underlying infrastructure. These practices are designed to support restoration of Services and Customer Data following certain operational disruptions.
Targeted Safeguards
Backup and recovery controls are applied based on the nature and criticality of the relevant systems and data.
Procedure Verification
Where appropriate, recovery procedures are periodically reviewed or tested to validate restoration capabilities.
Service Commitments
Specific service levels, recovery objectives, retention periods and disaster-recovery commitments, where applicable, are governed by the relevant Customer Agreement or service documentation.
Data Protection & Handling
Clear governance protecting customer ownership and rights.
No Sale & AI Non-Training
We do not sell Customer Data and, as described in our Responsible AI Disclosure, we do not use identifiable Customer Data to train general-purpose models absent a customer's written agreement.
Retention & Deletion Limits
Data retention and deletion are governed by the applicable Customer Agreement; where no specific term applies, we retain Customer Data only as long as reasonably necessary to provide the Services or as required by law.
Customer Data Deletion & Return
Customers can request deletion or return of their data in accordance with their Customer Agreement.
AI Security (AIRA, Sentio and Canopy)
Because AIRA, Sentio and Canopy incorporate AI-assisted functionality, Olive Branch considers security risks specific to AI systems in addition to general security controls.
Training data, embeddings, feature stores, inference components and other AI-related data or services are protected using controls appropriate to their function and risk.
Personnel & Endpoint Security
Human security practices that uphold operational integrity across all internal touchpoints.
Confidentiality Obligations
Personnel with access to Customer Data are subject to confidentiality obligations and security awareness practices appropriate to their role.
Role-Appropriate Training
Security training is provided as appropriate to personnel responsibilities and system access levels.
Restricted Access Scope
Personnel access to systems and Customer Data is restricted according to role and business need.
Vendor & Subprocessor Management
We maintain information regarding subprocessors used to provide the Services and, where applicable, provide customers with information regarding relevant providers, processing purposes and locations in accordance with the applicable Customer Agreement and Data Processing Agreement.
Compliance & Security Assurance
Olive Branch aligns its internal security policies and practices with recognized security and privacy principles and frameworks, as appropriate to our Services and customer requirements.
Recognized Principles & Frameworks
We align our internal security policies and practices with recognized security and privacy principles, ensuring robust baseline protections across AIRA, Sentio and Canopy.
Scaling Assurance Program
We are continuing to formalize and mature our compliance and assurance program as our platform and customer base scale.
Shared Responsibility
Security is a shared responsibility between Olive Branch and our customers. Customers are responsible for:
Olive Branch Responsibilities
- Securing the underlying cloud infrastructure and application environments.
- Enforcing encryption in transit and at rest with logical tenant segregation.
- Managing vulnerability scanning, regular patching, and testing of Services.
- Maintaining dedicated AI safeguards and incident response procedures.
Customer Responsibilities
- Managing user accounts, roles and permissions within their instance of the Services;
- Security of their own networks, devices and integrated systems;
- Promptly notifying us of suspected unauthorized access or security incidents affecting the Services;
- Configuring the Services consistent with their own internal security and compliance requirements; and
- Ensuring that data submitted to the Services may lawfully be processed for the customer's intended use.
Security built into how we operate.
Have questions about our security practices, AIRA, Sentio, or Canopy? Reach out to our dedicated security and compliance team.