How OkLau Technologies Inc. secures your mission-critical financial, HR, customer, and healthcare data with zero-trust architecture.
End-to-end encryption for all data in transit and at rest with hardware security modules (HSM).
Logical database partition and strict row-level security ensuring zero cross-tenant data leakage.
Continuous point-in-time recovery, hourly database backups, and multi-region disaster replication.
Built-in Business Associate Agreement (BAA) support, automated DSAR workflows, and audit logging.
OkLau ERP and product ecosystem are hosted in tier-IV enterprise cloud data centers (AWS & Google Cloud) equipped with redundant power, environmental controls, and biometric access restrictions. Network perimeters are guarded with automated DDoS mitigation, next-gen Web Application Firewalls (WAF), and automated TLS certificate provisioning via Caddy.
Every tenant organization operates within a segregated data environment. We enforce strict database scoping filters on every ORM query, preventing any unauthorized cross-tenant read or write operations. Enterprise users benefit from granular Role-Based Access Control (RBAC), multi-factor authentication (TOTP 2FA), and Single Sign-On (SAML 2.0 / OAuth2).
For healthcare customers using our Clinical and Health modules, OkLau offers formal Business Associate Agreements (BAA). We provide dedicated field-level encryption for Protected Health Information (PHI), audit access tracking with tamper-evident logs, and strict session expiration controls.
Our operational controls and information security management practices align with industry standards including SOC 2 Type II, ISO/IEC 27001, GDPR, and CCPA. Regular third-party penetration testing and vulnerability assessments are conducted to validate perimeter resilience.
Enterprise customers under NDA may request our latest SOC 2 report, ISO 27001 ISMS overview, or third-party penetration test executive summaries by emailing our security team at security@oklau.com.