Security at Overstory

Security is ingrained in our people, products, and processes, to ensure that your data is safeguarded.

Our controls are continuously monitored and assessed by Vanta, the leading automated security and compliance platform.

Security best practices

We follow the industry best practices for information security to protect our customers and their data.

Security threats are mitigated by adopting industry-accepted operational practices. Our systems leverage the Google Cloud Platform, an industry-leading secure-by-design cloud infrastructure platform.

We have a comprehensive set of policies and training material shared and completed by all employees.

Data protection

Our stringent governance and protection standards ensure that data is appropriately stored, processed and handled by our people and systems.

We follow the principle of least privilege to resources and data by users and systems in order to enhance fault tolerance and security.

All data is encrypted by default, both in transit and at rest. Encryption is performed with secure keys which are periodically rotated to mitigate compromises.

Data redundancy and versioning is built into our storage setup to minimise data loss.

Product security

We ensure that our product is secure by design in architecture, development and operation.To deliver a stable and secure product for our customers we perform routine threat modelling, peer reviews and security audits when building our product.

Our systems undergo rigorous security testing including automated scanning to identify potential threats. When threats are identified we have a stringent set of SLAs in place to ensure they are resolved in a timely manner.

Questions?

Get in touch with our security team for more information.