SECURITY & COMPLIANCE

Security built into how we operate.

Protecting the data our customers trust us with is core to how we build and operate AIRA, Sentio and Canopy. This page describes our current security program and the safeguards we use to protect customer data and the Services.

Notice:It supplements our Privacy Policy and Terms & Conditions and does not replace the specific commitments in a customer's Data Processing Agreement or Customer Agreement.

100% Encrypted

In transit & at rest

Role-Based Access

Strict least-privilege

Continuous Monitoring

Proactive incident response

Zero AI Training

No customer data model training

SECTION 01

Security Governance & Risk Management

Olive Branch maintains a risk-based security program designed to protect the confidentiality, integrity and availability of information processed through the Services. Our security practices are supported by documented policies, assigned responsibilities and controls appropriate to the nature and sensitivity of the information we process.

01

Risk Evaluation

Security risks are evaluated based on factors such as the nature of the information, the Services involved, the applicable use case and potential impact.

02

Control Prioritization

We periodically review security practices and controls and prioritize remediation of identified risks based on severity and potential impact.

03

Personnel Security

Personnel with access to Customer Data are subject to confidentiality obligations and security awareness requirements appropriate to their roles.

SECTION 02

Identity & Access Management

Access to customer environments and systems is governed by strictly defined protocols and verifiable need.

Role-Based Access & Least Privilege

Access to systems handling Customer Data is governed by role-based access and the principle of least privilege and need-to-know.

Privileged Access Controls

Authentication controls are applied to customer and internal access to the Services and supporting systems, with enhanced controls for privileged access where appropriate.

Lifecycle Access Reviews

Access rights are reviewed and adjusted as appropriate when personnel change roles or leave the organization.

SECTION 03

Infrastructure & Network Security

Olive Branch's Services are hosted on infrastructure provided by established cloud service providers. We rely on our providers' physical and environmental security controls for the data centers underlying our Services, and layer our own application-level, network-level and data-level controls on top of that infrastructure.

TIER 01: CLOUD HOST

Established Providers

Physical and environmental data center security managed by leading cloud providers.

TIER 02: NETWORK & APP

Layered Controls

Application-level, network-level and access controls layered above the infrastructure.

TIER 03: CRYPTOGRAPHY

Transit & Rest

Data is encrypted in transit and at rest using security controls appropriate to the applicable systems and data.

TIER 04: TENANCY

Logical Segregation

Customer Data is logically segregated by customer account, with controls designed to reduce unauthorized cross-customer access.

Production Safeguards: Production environments are subject to access controls, monitoring and other safeguards designed to reduce unauthorized access and operational risk.

SECTION 04

Secure Development & Vulnerability Management

Security considerations are incorporated into our software development and deployment processes. Controls applied to a particular change may vary based on its nature, scope and risk.

STEP 01

Monitoring

We maintain vulnerability-management practices that include monitoring for relevant vulnerabilities.

STEP 02

Assessment

Identified vulnerabilities are assessed based on factors such as severity, exploitability, and affected systems.

STEP 03

Prioritization

Remediation is prioritized according to assessed risk and potential impact across systems.

STEP 04

Patching

Regular patching of production infrastructure to maintain operational and software integrity.

STEP 05

Security Testing

We conduct or commission security testing appropriate to the nature and risk of the Services.

SECTION 05

Security Monitoring & Incident Response

Olive Branch maintains systematic incident-response procedures designed to identify, contain, investigate and remediate security incidents.

INCIDENT RESPONSE LIFECYCLE
1. Identify
2. Contain
3. Investigate
4. Remediate
5. Post-Incident Review

Escalation & Review

Incident response may include escalation, containment, investigation, remediation and post-incident review, as appropriate to the circumstances.

Customer Notification

We notify affected customers of a security incident in accordance with applicable contractual and legal obligations.

Testing & Exercises

We periodically review and, where appropriate, test our incident-response procedures and related escalation processes.

SECTION 06

Business Continuity, Backup & Disaster Recovery

Olive Branch maintains resilience, backup and recovery practices appropriate to the Services and the underlying infrastructure. These practices are designed to support restoration of Services and Customer Data following certain operational disruptions.

Targeted Safeguards

Backup and recovery controls are applied based on the nature and criticality of the relevant systems and data.

Procedure Verification

Where appropriate, recovery procedures are periodically reviewed or tested to validate restoration capabilities.

Service Commitments

Specific service levels, recovery objectives, retention periods and disaster-recovery commitments, where applicable, are governed by the relevant Customer Agreement or service documentation.

SECTION 07

Data Protection & Handling

Clear governance protecting customer ownership and rights.

No Sale & AI Non-Training

We do not sell Customer Data and, as described in our Responsible AI Disclosure, we do not use identifiable Customer Data to train general-purpose models absent a customer's written agreement.

Retention & Deletion Limits

Data retention and deletion are governed by the applicable Customer Agreement; where no specific term applies, we retain Customer Data only as long as reasonably necessary to provide the Services or as required by law.

Customer Data Deletion & Return

Customers can request deletion or return of their data in accordance with their Customer Agreement.

SECTION 08 • DEDICATED AI ARCHITECTURE

AI Security (AIRA, Sentio and Canopy)

Because AIRA, Sentio and Canopy incorporate AI-assisted functionality, Olive Branch considers security risks specific to AI systems in addition to general security controls.

SPECIFIC AI SECURITY RISK VECTORS EVALUATED
Unauthorized access to models or model-related data
Inappropriate data exposure through AI processing
Malicious or manipulated inputs & prompt-injection
Retrieval-related risks where relevant
Third-party model dependencies
Unintended AI outputs
AI PIPELINE SAFEGUARDS

Training data, embeddings, feature stores, inference components and other AI-related data or services are protected using controls appropriate to their function and risk.

Training Data
Embeddings
Feature Stores
Inference Engine
AI Services
SECTION 09

Personnel & Endpoint Security

Human security practices that uphold operational integrity across all internal touchpoints.

01

Confidentiality Obligations

Personnel with access to Customer Data are subject to confidentiality obligations and security awareness practices appropriate to their role.

02

Role-Appropriate Training

Security training is provided as appropriate to personnel responsibilities and system access levels.

03

Restricted Access Scope

Personnel access to systems and Customer Data is restricted according to role and business need.

SECTION 10

Vendor & Subprocessor Management

We maintain information regarding subprocessors used to provide the Services and, where applicable, provide customers with information regarding relevant providers, processing purposes and locations in accordance with the applicable Customer Agreement and Data Processing Agreement.

SUBPROCESSOR GOVERNANCE PRINCIPLES
1Identified processing purposes & geographic locations
2Alignment with Customer Agreements and DPAs
3Maintained subprocessor transparency
SECTION 11

Compliance & Security Assurance

Olive Branch aligns its internal security policies and practices with recognized security and privacy principles and frameworks, as appropriate to our Services and customer requirements.

FRAMEWORK ALIGNMENT

Recognized Principles & Frameworks

We align our internal security policies and practices with recognized security and privacy principles, ensuring robust baseline protections across AIRA, Sentio and Canopy.

CONTINUOUS MATURATION

Scaling Assurance Program

We are continuing to formalize and mature our compliance and assurance program as our platform and customer base scale.

SECTION 12

Shared Responsibility

Security is a shared responsibility between Olive Branch and our customers. Customers are responsible for:

OB

Olive Branch Responsibilities

  • Securing the underlying cloud infrastructure and application environments.
  • Enforcing encryption in transit and at rest with logical tenant segregation.
  • Managing vulnerability scanning, regular patching, and testing of Services.
  • Maintaining dedicated AI safeguards and incident response procedures.
CU

Customer Responsibilities

  • Managing user accounts, roles and permissions within their instance of the Services;
  • Security of their own networks, devices and integrated systems;
  • Promptly notifying us of suspected unauthorized access or security incidents affecting the Services;
  • Configuring the Services consistent with their own internal security and compliance requirements; and
  • Ensuring that data submitted to the Services may lawfully be processed for the customer's intended use.
SECURITY TRUST CENTER

Security built into how we operate.

Have questions about our security practices, AIRA, Sentio, or Canopy? Reach out to our dedicated security and compliance team.