Security at oklido

Security is fundamental to oklido. We understand you're trusting us with sensitive financial documents, and we take that responsibility seriously.

Our Security Commitment

oklido is built with security-first principles:

  • Defence in depth - Multiple layers of security controls
  • Zero trust architecture - Verify everything, trust nothing
  • Data minimisation - We only collect what we need
  • Transparency - Clear documentation of our practices

Certifications & Compliance

StandardStatusDescription
Cyber Essentials PlusCertifiedUK government-backed security certification
GDPRCompliantEU data protection regulation
UK DPA 2018CompliantUK Data Protection Act
SOC 2 Type IIIn progressService organisation controls

View compliance documentation →

Security Features

Data Protection Summary

AspectProtection
Documents at restAES-256 encryption
Data in transitTLS 1.3
Access controlRole-based (RBAC)
AuthenticationOAuth 2.0 via Auth0
Data residencyUK (AWS London eu-west-2)
BackupsEncrypted, geographically redundant

Security Practices

Regular Testing

  • Automated vulnerability scanning
  • Penetration testing (annual)
  • Dependency security audits
  • Code security reviews

Incident Response

We have documented procedures for:

  • Security incident detection
  • Rapid response and containment
  • Customer notification
  • Post-incident review

Learn more about incident response →

Employee Security

  • Background checks for all staff
  • Security awareness training
  • Principle of least privilege
  • Secure development training

Reporting Security Issues

If you discover a security vulnerability:

  1. Email: security@oklido.com
  2. Do not publicly disclose until resolved
  3. We aim to respond within 24 hours
  4. We do not pursue legal action against good-faith researchers

View our vulnerability disclosure policy →

Questions?

Contact our security team: security@oklido.com