What we protect, and how.
Owly handles bills — which means account numbers, addresses, and sometimes income details. The agency takes that seriously. Here is the honest version of our security posture.
Accountability you can verify.
Each milestone below is a public commitment. We update this trail when something ships, not when it's planned.
- Q1 2025Verified
Initial security review
Internal review against OWASP ASVS Level 1. Documented data flows, threat surfaces, and a remediation backlog.
- Q3 2025Verified
First independent audit
External penetration test focused on authentication, billing, and storage. Findings closed before publication.
- Q4 2025Verified
GDPR compliance certification
Data minimization, right-to-erasure, and DPA published. EU-region storage and export tooling shipped.
- Q1 2026In progress
SOC 2 Type II — observation begins
Readiness assessment complete. Observation window opened this quarter with a third-party CPA firm.
Five surfaces, one shield.
Everything an Owly investigation touches is encrypted, scoped to the case owner, and removable on request.