// Security & Compliance

What we do to keep your environment defensible.

This page is maintained by OdynCore Technology to answer common security and compliance questions about our services. It describes practices we operate, not an independent certification.

Access & authentication

  • MFA enforced for all engineer accounts
  • Least-privilege, role-based access to client systems
  • Quarterly access reviews with removal evidence

Monitoring & response

  • 24/7 endpoint and infrastructure monitoring
  • Documented incident response runbooks
  • Defined escalation and client notification path

Data protection

  • Encryption in transit and at rest
  • Immutable offsite backup in US and EU data centers
  • Tested restores on a quarterly schedule

Compliance support

  • SOC 2 readiness programs and evidence collection
  • HIPAA-ready control mapping for healthcare clients
  • PCI scope reduction reviews for retail clients

Shared responsibility

OdynCore operates the controls listed above within the scope defined in your agreement. Your organization remains responsible for internal policy approval, staff behavior, and any systems outside the agreed scope. Cloud and hosting providers remain responsible for their underlying platform controls.

Report a vulnerability

If you believe you have found a security issue in our systems or in a client environment we manage, email info@odyncore.co with the details. We acknowledge reports within one business day.

Certification status, audit reports and regulatory attestations are provided under NDA on request. Nothing on this page should be read as a certification issued by a third party.

Ready to see where you stand?

Book a free infrastructure assessment. We will map your risks, gaps and quick wins in one session.