Last updated: February 16, 2026
TLS 1.2+
All data encrypted in transit
AES-256
Database encrypted at rest
SOC 2 Infrastructure
Vercel + Supabase + Anthropic + OpenAI
PCI DSS Payments
Via Lemon Squeezy (merchant of record)
No Data Training
AI providers don't train on your data
Row-Level Security
Database isolation per user
GDPR / CCPA / LGPD
10-region privacy compliance
Responsible Disclosure
90-day security vulnerability program
Transparency note: Otoq is an early-stage product. We do not yet have an independent third-party security audit. The practices described below are self-assessed and reflect our actual implementation. Our infrastructure providers (Vercel, Supabase, Anthropic, OpenAI) each maintain their own SOC 2 Type II certifications, which you can verify via their respective trust pages. We plan to pursue independent certification as we scale.
At Otoq, security is foundational — not an afterthought. We handle your business data and your customers' conversations, and we take that responsibility seriously. This page describes how we protect your data and how you can help us keep the platform secure.
We are committed to complying with data protection laws across all jurisdictions we serve. See our Privacy Policy (Region-Specific Addendums) for jurisdiction-specific details.
| Region | Regulation | Status |
|---|---|---|
| Philippines | Data Privacy Act (RA 10173) | Compliant |
| EU / EEA | General Data Protection Regulation (GDPR) | Compliant |
| United Kingdom | UK GDPR + Data Protection Act 2018 | Compliant |
| California, US | CCPA / CPRA | Compliant — no data sales |
| Brazil | Lei Geral de Proteção de Dados (LGPD) | Compliant |
| Canada | PIPEDA | Compliant |
| South Africa | POPIA | Compliant |
| Singapore | Personal Data Protection Act (PDPA) | Compliant |
| Australia | Privacy Act 1988 (APPs) | Compliant |
| Japan | Act on Protection of Personal Information (APPI) | Compliant |
We welcome security researchers to help us keep Otoq safe. If you discover a vulnerability, please report it responsibly:
We commit to acknowledging receipt within 48 hours and providing regular updates on our progress. We will not take legal action against researchers who follow these guidelines.
| Service | Purpose | Compliance |
|---|---|---|
| Vercel | Application hosting | SOC 2 Type II, GDPR |
| Supabase | Database, Auth, Storage | SOC 2 Type II, HIPAA, GDPR |
| Anthropic | AI responses (Claude) | SOC 2 Type II, no data training |
| OpenAI | Text embeddings | SOC 2 Type II, no data training |
| Lemon Squeezy | Payment processing | PCI DSS, GDPR |
| Upstash | Rate limiting (Redis) | SOC 2 Type II, GDPR |
| Resend | Transactional email | GDPR |
| Shopify | E-commerce integration | SOC 2 Type II, PCI DSS, GDPR |
| Sentry | Error tracking | SOC 2 Type II, GDPR |
| PostHog | Product analytics | SOC 2 Type II, GDPR, HIPAA |
For security concerns: security@getotoq.com
For privacy questions: privacy@getotoq.com
For general support: support@getotoq.com