// Security & Compliance
What we do to keep your environment defensible.
This page is maintained by OdynCore Technology to answer common security and compliance questions about our services. It describes practices we operate, not an independent certification.
Access & authentication
- MFA enforced for all engineer accounts
- Least-privilege, role-based access to client systems
- Quarterly access reviews with removal evidence
Monitoring & response
- 24/7 endpoint and infrastructure monitoring
- Documented incident response runbooks
- Defined escalation and client notification path
Data protection
- Encryption in transit and at rest
- Immutable offsite backup in US and EU data centers
- Tested restores on a quarterly schedule
Compliance support
- SOC 2 readiness programs and evidence collection
- HIPAA-ready control mapping for healthcare clients
- PCI scope reduction reviews for retail clients
Shared responsibility
OdynCore operates the controls listed above within the scope defined in your agreement. Your organization remains responsible for internal policy approval, staff behavior, and any systems outside the agreed scope. Cloud and hosting providers remain responsible for their underlying platform controls.
Report a vulnerability
If you believe you have found a security issue in our systems or in a client environment we manage, email info@odyncore.co with the details. We acknowledge reports within one business day.
Certification status, audit reports and regulatory attestations are provided under NDA on request. Nothing on this page should be read as a certification issued by a third party.
Ready to see where you stand?
Book a free infrastructure assessment. We will map your risks, gaps and quick wins in one session.
