Security and Compliance
Security & Compliance
Audit-ready because of how it is built — not because of a report you run.
ODS holds employee records, signed documents, and training histories: the material an auditor, a regulator, or a client asks for with short notice. It is designed so producing that material is a query, not a project.
Four things that are true on every plan
Security is not a tier in ODS. These are properties of the platform, not features you buy up to.
Encrypted access and storage
Data is encrypted in transit and at rest. Every session is authenticated before a single record is returned.
Immutable audit log
Every record change is written to a log that cannot be edited or deleted — including by administrators.
Multi-level admin controls
Administrator is not one switch. Access is granular by department, role, and record type.
Audit-ready reporting
Evidence is exported from live records. You are not assembling a binder from four systems.
The question that decides everything
“Show me that this employee completed the required training before they touched the equipment — and prove the record has not been altered since.”
Most organisations can eventually answer that. The cost is a week of someone cross-referencing an LMS export against an HR spreadsheet against an email thread — and an answer nobody can fully vouch for.
In ODS the completion, the timestamp, the version of the course, and the person who assigned it are one linked record. Answering takes a filter, not a project.
How access control actually works
The most common security failure in workforce systems is not a breach. It is a manager who can see salary data, or a departed employee whose login still works.
Scoped to the org chart
Permissions follow the structure you already maintain. A department head sees their department — not because someone remembered to configure it, but because the seat defines it.
Separated by record type
Training history, signed documents, and compensation are distinct permissions. Access to one does not imply access to another.
Closed on departure
Offboarding revokes access as part of the lifecycle, not as a ticket someone files afterwards. The record stays; the access does not.
What we do not claim
ODS is in early access, and we would rather be exact than impressive. If a certification matters to your procurement process, ask us on the call and you will get a direct answer about where we are — not a badge on a page.
We answer security questionnaires
Send us your standard vendor assessment. We complete it properly rather than pointing you at a marketing page, and we will tell you plainly where a control is designed but not yet independently attested.
We support your client reviews
If your own customers audit your subprocessors, we will join that conversation. For federal contractors and diagnostic labs this is usually the real requirement, and it is why the Secure plan exists.
Questions procurement asks us
Who can see an employee’s records?
Only roles you have explicitly granted, scoped to the part of the org chart they own. Access is auditable — you can see who viewed what.
Can an administrator alter a completed training record?
They can correct data, but the change is written to the immutable log with the actor and timestamp. Nothing disappears silently. That is the point of the log.
What happens to our data if we leave?
You export it. Records, documents, and training histories you created remain yours — that holds whether the partnership continues or ends.
Can we set our own retention policy?
On the Secure plan, yes. Retention windows and access policies can be configured to match what your regulator or client contract requires.
Do you support single sign-on?
Bring this to the demo call with your identity provider named. We will tell you exactly what is supported today rather than what is on a roadmap.
Bring your security questionnaire
Twenty minutes, end to end, on real data. Bring the questions your auditor or your biggest client asks — we would rather answer them now than after you have committed.
