OLY.AI Inc. SOC2 Compliance

# OLY.AI

## SOC 2 Security Summary

# Security • Availability • Confidentiality

---

#### Section 1: Overview

**OLY.AI is an AI-powered financial intelligence platform built on Google Cloud Platform with a QuickBooks Online Certified integration. Security, confidentiality, and availability are foundational to the platform’s design.**

---

#### Section 2: Security Highlights

**Infrastructure**

* **Google Cloud Platform**

* **SOC 1, SOC 2, ISO certified**

**Data Protection**

* **TLS encryption**

* **Encrypted storage**

* **Tenant isolation**

**Access Controls**

* **RBAC**

* **Least privilege**

* **Environment separation**

---

#### Section 3: QuickBooks Integration

* **OAuth 2.0 authentication**

* **No passwords stored**

* **Read-only, scoped access**

* **Revocable tokens**

---

#### 

#### Section 4: Privacy & AI

* **Data minimization**

* **No data resale**

* **No foundation model training on customer data**

* **Secure deletion workflows**

---

#### Section 5: Availability & Incident Response

* **Multi-zone cloud architecture**

* **Monitoring & alerting**

* **Backup & recovery**

* **Incident response procedures**

---