๐Ÿ›ก๏ธ Trust & Security Center

Enterprise Security & Compliance

How OkLau Technologies Inc. secures your mission-critical financial, HR, customer, and healthcare data with zero-trust architecture.

๐Ÿ”’

AES-256 & TLS 1.3

End-to-end encryption for all data in transit and at rest with hardware security modules (HSM).

๐Ÿ›๏ธ

Multi-Tenant Isolation

Logical database partition and strict row-level security ensuring zero cross-tenant data leakage.

โฑ๏ธ

Automated Snapshots

Continuous point-in-time recovery, hourly database backups, and multi-region disaster replication.

๐Ÿ“œ

HIPAA & GDPR Controls

Built-in Business Associate Agreement (BAA) support, automated DSAR workflows, and audit logging.

1. Infrastructure Security & Cloud Architecture

OkLau ERP and product ecosystem are hosted in tier-IV enterprise cloud data centers (AWS & Google Cloud) equipped with redundant power, environmental controls, and biometric access restrictions. Network perimeters are guarded with automated DDoS mitigation, next-gen Web Application Firewalls (WAF), and automated TLS certificate provisioning via Caddy.

2. Tenant Data Isolation & Zero-Trust Access

Every tenant organization operates within a segregated data environment. We enforce strict database scoping filters on every ORM query, preventing any unauthorized cross-tenant read or write operations. Enterprise users benefit from granular Role-Based Access Control (RBAC), multi-factor authentication (TOTP 2FA), and Single Sign-On (SAML 2.0 / OAuth2).

3. Healthcare & HIPAA Compliance

For healthcare customers using our Clinical and Health modules, OkLau offers formal Business Associate Agreements (BAA). We provide dedicated field-level encryption for Protected Health Information (PHI), audit access tracking with tamper-evident logs, and strict session expiration controls.

4. Compliance Standards & Certifications

Our operational controls and information security management practices align with industry standards including SOC 2 Type II, ISO/IEC 27001, GDPR, and CCPA. Regular third-party penetration testing and vulnerability assessments are conducted to validate perimeter resilience.

5. Requesting Security Reports & Audits

Enterprise customers under NDA may request our latest SOC 2 report, ISO 27001 ISMS overview, or third-party penetration test executive summaries by emailing our security team at security@oklau.com.

Have specific compliance or vendor assessment questions?
Our security & compliance engineering team is available to assist your IT audit.
Contact Security Team โ†’
โ† Back to OkLau Home Privacy Policy Terms of Service DPA