Your data, handled carefully.
OSPattern is new. Rather than a wall of badges, here is plainly what the platform does today, what happens at launch, and what is still planned. We’ll keep this page current.
Where things stand
| Area | What it means | Status |
|---|---|---|
| Encryption of sensitive fields | Fields marked sensitive — phone numbers, ID numbers, health details — are encrypted before they are stored, not just the disk they sit on. | Built |
| Encrypted files | Documents and photos in sensitive fields are encrypted, their type is checked from their contents, and every download of personal files is recorded. | Built |
| Encryption in transit | All traffic to OSPattern uses HTTPS (TLS). | At launch |
| Sessions | Sign-in sessions are short-lived and expire on their own. Repeated failed sign-in attempts are rate-limited. | Built |
| Two-factor sign-in | Codes from an authenticator app, in addition to a password. | Built |
| Approvals with maker-checker | Requests go to the right approver — a manager, a role or a named person. Whoever submits can never approve their own request, and every decision and its reason is kept. | Built |
| Password reset and invitations | People join by email invitation and reset forgotten passwords with single-use links that expire in 30 minutes. Signing out ends that device’s notifications too. | Built |
| Roles and access | Access is decided per role, down to individual records and fields. The runtime enforces it, not each screen. | Built |
| Audit trail | A record of who viewed or changed data, and every published change to an app’s pattern. | Built |
| Data residency | Each workspace chooses where its data lives: India or the EU. It stays there. | Built |
| Hosting | AWS, Mumbai region (ap-south-1) for India; Frankfurt (eu-central-1) for EU customers. | At launch |
| Export and erasure | Export a person’s data, or erase their personal and sensitive values, to answer DPDP and GDPR requests. | Built |
| Backups | Automated, encrypted backups kept in the same region as the data. | At launch |
| Single sign-on (SAML / OIDC) | Sign in with your company’s identity provider. | Planned |
| Independent audits | Third-party penetration testing and a formal security certification. | Planned |
How we think about it
Once, in the runtime
Security is built into the platform every app runs on. A new app doesn’t need its own access control, audit or encryption — and can’t forget them.
Minimum by default
People see only what their role needs. Sensitive fields are hidden unless someone is explicitly allowed to see them, and viewing them is recorded.
Changes are visible
Every change to how an app works is drafted, reviewed and published as a version. You can always see what changed, who approved it, and revert.
DPDP Act, 2023
OSPattern is built so that you, as the data fiduciary, can meet your obligations: consent records, purpose-limited access, correction and erasure, and data kept in India.
GDPR
For EU customers: data kept in the EU, access and erasure requests supported, and a data processing agreement for customers who need one.
“DPDP-ready” and “GDPR-ready” mean the platform has the controls you need. Compliance also depends on how each business uses it; we’re happy to walk through it with your team.
Found a security issue?
Please write to us before sharing it publicly. We’ll acknowledge it and keep you updated while we fix it.