# Enterprise security, built in.

Security is foundational to how we build and operate Openlayer. We embed security into every stage of software development, infrastructure, and operations to protect your data, meet enterprise standards, and earn your trust.

## By the numbers

| Stat | Meaning |
| --- | --- |
| 99.9% | platform availability |
| AES-256 | encryption at rest |
| TLS 1.2+ | encryption in transit |

## Independently validated. Enterprise ready

Openlayer maintains security and privacy controls designed to meet the requirements of enterprise organizations operating in regulated industries.

- SOC 2 Type II
- GDPR
- HIPAA

## Openlayer's security

### Role-based access control

Assign roles and permissions for appropriate access across your organization.

### Single sign-on (SSO)

Secure, one-click authentication using Google SSO.

### SAML and OIDC

Support for SAML and OIDC with identity providers like Okta.

### Directory sync

Manage workspace members via third-party identity provider integrations.

### Air-gapped deployments

Deploy Openlayer in your own VPC with no external network connections.

### Data encryption

HTTPS and TLS 1.2 for data in transit, and AES 256-bit encryption at rest.

### Automated backups

Redundant storage with fully automated backups to prevent data loss.

### Multi-region hosting

Store your data in the EU or the US for optimal regulatory compliance.

## We continuously validate our security posture.

Openlayer runs penetration tests with independent security firms and performs daily code review, static analysis, and dependency scanning. SOC 2 Type II compliance is monitored continuously with Vanta.

- Insight Partners
- Vanta

## Continuous Security Operations

Security is never finished.

Security controls are continuously monitored and regularly reviewed to maintain a strong security posture as our platform evolves.

Our operational security program includes:

- Continuous vulnerability scanning
- Dependency monitoring
- Infrastructure monitoring
- Security logging and alerting
- Third-party penetration testing
- Incident response procedures
- Disaster recovery planning
- Automated backup verification

## Ship with confidence.

See your first AI system tested, monitored, and audit-ready in one demo.
