Security at OptiMe

    Your trust is paramount. We build privacy and security into every layer of OptiMe, from the code we write to the infrastructure we run on.

    GDPR aligned
    UK hosted
    TLS 1.3

    Data Encryption

    Encryption in Transit

    All data transmitted between your device and our servers is protected using TLS 1.3 encryption.

    Encryption at Rest

    Your data is encrypted using AES-256 when stored in our databases, ensuring protection even in the unlikely event of a breach.

    Infrastructure Security

    Our infrastructure is hosted in the United Kingdom on an enterprise cloud platform with robust security controls, network isolation, and automated patching.

    DDoS Protection

    Automatic mitigation of distributed denial-of-service attacks

    Web Application Firewall

    Protection against common web vulnerabilities

    Regular Backups

    Automated daily backups with point-in-time recovery

    Network Isolation

    Segmented networks with strict access controls

    Intrusion Detection

    Continuous monitoring for suspicious activity

    Disaster Recovery

    Multi-region redundancy for business continuity

    Access Control

    Role-Based Access

    Strict role-based access control ensures users only access data necessary for their role. Organisation administrators cannot see individual employee wellbeing scores.

    Secure Authentication

    Passwords are hashed with industry-standard algorithms. Breached-password protection is enabled, and all authentication flows run over TLS 1.3.

    Session Management

    Automatic session timeouts and secure token management protect against unauthorised access.

    Compliance

    GDPR

    Aligned with the UK GDPR and EU GDPR, including data minimisation, purpose limitation, and the right to erasure.

    Anonymous Reporting

    Organisation reports are anonymised aggregates. Managers never see individual scores, and reports require a minimum response threshold.

    Privacy by Design

    Privacy is embedded into every aspect of our product development process:

    • Data minimisation — we only collect what's necessary for the service
    • Purpose limitation — data is only used for stated purposes
    • User consent — explicit consent before processing personal data
    • Data portability — easily export your data in standard formats
    • Right to erasure — request complete deletion of your data
    • Transparency — clear communication about data practices

    Vulnerability Disclosure

    We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to us promptly.

    Please include detailed information about the vulnerability, steps to reproduce, and your contact information. We commit to acknowledging reports within 48 hours and will keep you informed of our remediation progress.

    Questions About Security?

    Our security team is here to help with any questions or concerns.