Compliance

oklido maintains compliance with major security and data protection standards.

Certifications

CertificationStatusLast Audit
Cyber Essentials PlusCertified2025
GDPRCompliantOngoing
UK DPA 2018CompliantOngoing
SOC 2 Type IIIn progressExpected 2026

Compliance Documentation

Data Protection

Legal Basis for Processing

We process data under the following legal bases (GDPR Article 6):

PurposeLegal Basis
Providing the serviceContract performance
Account managementContract performance
Security monitoringLegitimate interest
Product improvementLegitimate interest
Marketing (opt-in only)Consent
Legal complianceLegal obligation

Your Rights

Under GDPR and UK DPA 2018, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Port your data to another service
  • Object to certain processing
  • Restrict processing in certain circumstances

Exercise your rights →

Security Controls

oklido implements the following security controls:

ControlImplementation
Encryption at restAES-256
Encryption in transitTLS 1.3
Access controlRBAC with least privilege
AuthenticationOAuth 2.0 / MFA
LoggingComprehensive audit trails
Monitoring24/7 automated monitoring
Vulnerability managementRegular scanning and patching
Incident responseDocumented procedures

Requesting Compliance Documents

For detailed compliance documentation, contact us:

  • Email: compliance@oklido.com
  • Available documents:
    • Data Processing Agreement (DPA)
    • Security questionnaire responses
    • Penetration test executive summary
    • SOC 2 report (when available)

Audit Rights

Enterprise customers may request:

  • Right to audit (with reasonable notice)
  • Third-party audit reports
  • Security questionnaire completion
  • Custom DPA terms

Contact sales@oklido.com for enterprise compliance requirements.