OLY.AI Inc. SOC2 Compliance
# OLY.AI
## SOC 2 Security Summary
# Security • Availability • Confidentiality
---
#### Section 1: Overview
**OLY.AI is an AI-powered financial intelligence platform built on Google Cloud Platform with a QuickBooks Online Certified integration. Security, confidentiality, and availability are foundational to the platform’s design.**
---
#### Section 2: Security Highlights
**Infrastructure**
* **Google Cloud Platform**
* **SOC 1, SOC 2, ISO certified**
**Data Protection**
* **TLS encryption**
* **Encrypted storage**
* **Tenant isolation**
**Access Controls**
* **RBAC**
* **Least privilege**
* **Environment separation**
---
#### Section 3: QuickBooks Integration
* **OAuth 2.0 authentication**
* **No passwords stored**
* **Read-only, scoped access**
* **Revocable tokens**
---
####
#### Section 4: Privacy & AI
* **Data minimization**
* **No data resale**
* **No foundation model training on customer data**
* **Secure deletion workflows**
---
#### Section 5: Availability & Incident Response
* **Multi-zone cloud architecture**
* **Monitoring & alerting**
* **Backup & recovery**
* **Incident response procedures**
---