Trust & policy

Security & compliance

OSTaaS.cloud uses isolated environments, least-privilege access, evidence trails, and documented change control across testing engagements.

How we protect engagements

Isolated environments

Every engagement runs in a dedicated sandbox with its own network boundaries. Test workloads never share runtime state with other customers.

Least-privilege access

Access is scoped per engagement and granted only for the duration of active work. Credentials are rotated and revoked on hand-over.

Evidence trails

Each validation step is recorded to an auditable trail so results can be reviewed, reproduced, and attributed to a specific run.

Documented change control

Infrastructure and test configuration changes are version-controlled and reviewed before they are applied to an engagement.

Observability

Sandboxes are instrumented so behaviour, health checks, and failures are captured and available for review during and after testing.

Data handling

We work with the minimum data required to validate a system. Recordings and artefacts are reviewed for redaction before anything is shared.

Compliance posture

Our assessment methodology can map operational evidence to SOC 2-aligned controls. To be clear about scope: OSTaaS.cloud is not a certification body and does not issue ISO 27001 or SOC 2 certificates. We produce the evidence and hardening guidance your auditors and internal teams can rely on.

Responsible disclosure

Found a security concern? Email security@ostaas.cloud with enough detail for us to reproduce and investigate it. We aim to acknowledge reports promptly and will keep you updated through resolution.

Contact support