Security & privacy

Your data, handled carefully.

OSPattern is new. Rather than a wall of badges, here is plainly what the platform does today, what happens at launch, and what is still planned. We’ll keep this page current.

Where things stand

Builtin the platform now, being hardened with pilot partners At launchin place when we open to customers Plannedon the roadmap, not yet built
AreaWhat it meansStatus
Encryption of sensitive fields

Fields marked sensitive — phone numbers, ID numbers, health details — are encrypted before they are stored, not just the disk they sit on.

Built
Encrypted files

Documents and photos in sensitive fields are encrypted, their type is checked from their contents, and every download of personal files is recorded.

Built
Encryption in transit

All traffic to OSPattern uses HTTPS (TLS).

At launch
Sessions

Sign-in sessions are short-lived and expire on their own. Repeated failed sign-in attempts are rate-limited.

Built
Two-factor sign-in

Codes from an authenticator app, in addition to a password.

Built
Approvals with maker-checker

Requests go to the right approver — a manager, a role or a named person. Whoever submits can never approve their own request, and every decision and its reason is kept.

Built
Password reset and invitations

People join by email invitation and reset forgotten passwords with single-use links that expire in 30 minutes. Signing out ends that device’s notifications too.

Built
Roles and access

Access is decided per role, down to individual records and fields. The runtime enforces it, not each screen.

Built
Audit trail

A record of who viewed or changed data, and every published change to an app’s pattern.

Built
Data residency

Each workspace chooses where its data lives: India or the EU. It stays there.

Built
Hosting

AWS, Mumbai region (ap-south-1) for India; Frankfurt (eu-central-1) for EU customers.

At launch
Export and erasure

Export a person’s data, or erase their personal and sensitive values, to answer DPDP and GDPR requests.

Built
Backups

Automated, encrypted backups kept in the same region as the data.

At launch
Single sign-on (SAML / OIDC)

Sign in with your company’s identity provider.

Planned
Independent audits

Third-party penetration testing and a formal security certification.

Planned

How we think about it

Once, in the runtime

Security is built into the platform every app runs on. A new app doesn’t need its own access control, audit or encryption — and can’t forget them.

Minimum by default

People see only what their role needs. Sensitive fields are hidden unless someone is explicitly allowed to see them, and viewing them is recorded.

Changes are visible

Every change to how an app works is drafted, reviewed and published as a version. You can always see what changed, who approved it, and revert.

India

DPDP Act, 2023

OSPattern is built so that you, as the data fiduciary, can meet your obligations: consent records, purpose-limited access, correction and erasure, and data kept in India.

European Union

GDPR

For EU customers: data kept in the EU, access and erasure requests supported, and a data processing agreement for customers who need one.

“DPDP-ready” and “GDPR-ready” mean the platform has the controls you need. Compliance also depends on how each business uses it; we’re happy to walk through it with your team.

Found a security issue?

Please write to us before sharing it publicly. We’ll acknowledge it and keep you updated while we fix it.

Report an issue