SOC 2 Type II Certified ISO 27001 Certified

Enterprise-Grade Security

Your data is protected by industry-leading security practices, encryption standards, and compliance certifications.

99.99%
Uptime SLA
256-bit
Encryption (AES)
24/7
Security Monitoring
Annual
Penetration Testing

Compliance Certifications

SOC 2 Type II

Security, Availability, Confidentiality

ISO 27001

Information Security Management

PCI DSS Level 1

Payment Card Industry Compliance

GDPR Compliant

EU Data Protection Regulation

*Certifications available upon request under NDA

Encryption Standards

Data at Rest:

AES-256 encryption for all databases, backups, and stored files.

Data in Transit:

TLS 1.3 for all API endpoints, web traffic, and internal communications.

Key Management:

AWS KMS with automatic key rotation every 90 days.

End-to-End Encryption:

SMS content is never stored permanently; processed in memory only.

Secure Infrastructure

Our infrastructure is hosted on AWS with multiple availability zones for high availability and disaster recovery.

  • Multi-Region Deployment: US-East, EU-West, AP-Southeast
  • DDoS Protection: AWS Shield Advanced + Cloudflare
  • WAF: Web Application Firewall with OWASP Top 10 rules
  • VPC Isolation: All services in private subnets with no direct internet access
  • Backup & DR: Automated daily backups with 30-day retention

Data Protection

We implement multiple layers of data protection:

Data Masking Tokenization Data Minimization PII Redaction DLP Policies

SMS content (OTP codes) is processed in real-time and permanently deleted immediately after delivery. We do not store message content in any persistent storage.

Access Control

  • Principle of Least Privilege: Role-based access control (RBAC)
  • Multi-Factor Authentication: Required for all employee access
  • SSO Integration: SAML 2.0 for enterprise customers
  • Just-in-Time Access: Temporary credentials for production systems
  • Regular Access Reviews: Quarterly audits of all permissions

Monitoring & Auditing

24/7 security monitoring with automated alerting and SIEM integration.

  • • Real-time threat detection and anomaly identification
  • • Centralized logging with 12-month retention
  • • Automated vulnerability scanning (daily)
  • • Annual third-party penetration testing
  • • Continuous compliance monitoring

Incident Response

Our incident response plan includes:

  • • Dedicated 24/7 security on-call team
  • <1 hour initial response for critical incidents
  • <4 hours containment and mitigation
  • • Customer notification within 24 hours for data breaches
  • • Post-incident review and remediation

Responsible Vulnerability Disclosure

We welcome security researchers to report vulnerabilities responsibly. Please follow our disclosure policy:

  • • Email findings to security@otpsims.com
  • • Allow us 90 days to address reported issues
  • • Do not exploit vulnerabilities beyond necessary proof
  • • Do not access or modify user data

We participate in bug bounty programs. Eligible reports may receive recognition and compensation.

Compliance Frameworks

GDPR CCPA PIPEDA HIPAA SOX FERPA

We provide compliance documentation including Data Processing Agreements, SOC 2 reports, and security questionnaires upon request.

Third-Party Security

All third-party vendors undergo rigorous security assessment including:

  • • Security questionnaire review
  • • SOC 2 or ISO 27001 certification verification
  • • Data processing agreement execution
  • • Regular re-assessment (annual)

Current key vendors: AWS, Stripe, Cloudflare, Datadog, Sentry

Contact Security Team

Security Questions: security@otpsims.com

Vulnerability Reports: security@otpsims.com (PGP key available)

Compliance Documentation: compliance@otpsims.com

PGP Fingerprint: 1234 5678 90AB CDEF 1234 5678 90AB CDEF 1234 5678

OTPSims maintains an industry-leading security posture. We are continuously audited and certified by independent third parties.