Enterprise security,built in.
Security is foundational to how we build and operate Openlayer. We embed security into every stage of software development, infrastructure, and operations to protect your data, meet enterprise standards, and earn your trust.
Request security documentation99.9%
platform availability
AES-256
encryption at rest
TLS 1.2+
encryption in transit
Independently validated. Enterprise ready
Openlayer maintains security and privacy controls designed to meet the requirements of enterprise organizations operating in regulated industries.
SOC 2
Type II
SOC 2 Type II
GDPR
GDPR
HIPAA
HIPAA
Openlayer’ssecurity
Role-based access control
Assign roles and permissions for appropriate access across your organization.
Single sign-on (SSO)
Secure, one-click authentication using Google SSO.
SAML and OIDC
Support for SAML and OIDC with identity providers like Okta.
Directory sync
Manage workspace members via third-party identity provider integrations.
Air-gapped deployments
Deploy Openlayer in your own VPC with no external network connections.
Data encryption
HTTPS and TLS 1.2 for data in transit, and AES 256-bit encryption at rest.
Automated backups
Redundant storage with fully automated backups to prevent data loss.
Multi-region hosting
Store your data in the EU or the US for optimal regulatory compliance.
We continuouslyvalidate our security posture.
Openlayer runs penetration tests with independent security firms and performs daily code review, static analysis, and dependency scanning. SOC 2 Type II compliance is monitored continuously with Vanta.
Insight Partners
Vanta
Continuous Security Operations Security is never finished.
Security controls are continuously monitored and regularly reviewed to maintain a strong security posture as our platform evolves.
Our operational security program includes:
Continuous vulnerability scanning
Dependency monitoring
Infrastructure monitoring
Security logging and alerting
Third-party penetration testing
Incident response procedures
Disaster recovery planning
Automated backup verification
Is Openlayer SOC 2 Type II certified?
Yes, Openlayer holds SOC 2 Type II certification, with compliance monitored on an ongoing basis rather than checked once a year. Openlayer is also GDPR compliant and supports HIPAA-aligned use cases.
How does Openlayer encrypt data at rest?
Data at rest is encrypted using AES-256, the encryption standard commonly required by regulated enterprise security policies.
How is data encrypted in transit?
Data in transit is encrypted using TLS 1.2 or higher, so information moving between a customer's systems and Openlayer is protected in addition to data at rest.
Does Openlayer support SSO/SAML?
Openlayer supports single sign-on through Google, SAML, and OIDC, so organizations can connect Openlayer to identity providers such as Okta instead of managing separate credentials.
Does Openlayer support RBAC?
Openlayer supports role-based access control, letting administrators define what each user or team can see and do inside the platform rather than granting the same access to everyone.
Can Openlayer run in a VPC or on-premises?
Openlayer supports deployment inside a customer's own virtual private cloud, and on-premise deployment is available on the Enterprise plan for organizations with stricter infrastructure requirements.
Does Openlayer support air-gapped environments?
Yes, Openlayer offers air-gapped deployment options with no external network connections, for organizations that cannot allow AI governance data to leave their own environment.
How is customer data handled?
Customer data is encrypted at rest and in transit, backed up automatically with redundant storage, and hosted in a choice of regions to support data residency requirements such as keeping data in the EU or the US.
What are the data retention options?
Retention is configurable rather than fixed. The Basic plan includes three months of retention on a single workspace, while Enterprise customers can set custom retention periods to match their own compliance requirements.
Where can I review Openlayer's security documentation?
Security documentation, including details on certifications, architecture, and penetration testing, is available on request. The fastest way to request it is through the Openlayer team via a demo or sales conversation.
Ship with confidence.
See your first AI system tested, monitored, and audit-ready in one demo.



