SOC 2: Olto Discovery is built on security-conscious infrastructure with SOC 2-aligned controls in mind, but it has not undergone a SOC 2 audit as of this writing. We rely on infrastructure providers with established security programs, including SOC 2-compliant vendors where available.
HIPAA / PHI: Olto Discovery is not, by default, a HIPAA-covered platform. A HIPAA-capable configuration with a Business Associate Agreement (BAA) is available for Enterprise customers under a separately scoped enterprise agreement. Until such an agreement is in place, do not upload protected health information.
Transport & encryption: Data is encrypted in transit (TLS) and at rest (AES-256), but the Service is not end-to-end encrypted — AI prompts, uploaded files, and conversations are sent to our AI provider to function. HTTP Strict Transport Security (HSTS) is not currently enforced; connections are still served over HTTPS with HTTP redirected to it.
Restricted data: Unless expressly permitted in a signed Enterprise agreement with an appropriate compliance configuration, do not upload PHI, patient-identifiable clinical data, classified information, export-controlled data, controlled unclassified information (CUI), or other regulated sensitive data.
For where we align (and where we do not yet) with NIST CSF 2.0, OWASP ASVS L2, the NIST 800-series, and our FIPS-approved crypto posture — stated honestly, including what remains — see the Compliance & Trust page.