octobid.net
Trust Center
What we run, how it is monitored, and the evidence behind it — published for security reviewers and procurement teams.
⚠ Attention items open · snapshot 2026-07-19 · NIST 800-171 self-assessment 103/110 (self-assessment 2026-07)
Controls in production
- Encryption everywhere. TLS at the edge; documents in private object storage; AES-256 encrypted off-site disaster-recovery snapshots on independent infrastructure.
- Tenant isolation. Every workspace's data is scoped to its tenant at the database and object-key level.
- Hardened runtime. Read-only containers, dropped Linux capabilities, no privilege escalation, key-only SSH, brute-force protection.
- Backups that restore. Daily database backups, an encrypted remote mirror, and a weekly automated restore drill that proves recovery works.
- Continuous monitoring. Graded alerting (major / warning / notice) on data pipelines, backups, and services; monthly container vulnerability scans.
- Change control. Every production change passes type checking and lint gates and ships through scripted, logged deploys from version control.
- AI data handling. Your documents generate your drafts. We never train models on customer content or share content across tenants.
Compliance posture
- NIST SP 800-171.Documented SSP and POA&M, first scored self-assessment 103/110 (July 2026), quarterly reviews scheduled.
- SOC 2. Audit-ready: policy set adopted, system description drafted, evidence collected automatically every month into an auditor-ready package. A Type I examination by an independent CPA firm will be engaged on customer demand; this page will host the report.
- Scope. Octobid is not an authorized environment for CUI or export-controlled material — see the Security & Data Handling policy.
Security reviewers: request the current evidence package or ask questions at [email protected] (subject SECURITY). We answer within two business days.