Skip to content
security_header
security_header

Security

At Opus 2, security is built into everything we do. We are an ISO:27001 certified organisation, committed to protecting your data and privacy.

Compliance and certification

We provide a secure alternative to information sharing, process management, and collaboration methods that can put your data at risk. We meet stringent industry standards and have:
  • maintained ISO27001:2013 certification since 2015
  • retained Cyber Essentials Plus certification since 2016
  • been listed as a GovCloud provider for data
  • built a comprehensive Privacy Management Framework that we will seek to certify against the prevailing GDPR Compliance Standard once it is available

Thumb_mark-of-trust-certified-ISO-9001-quality-management-systems-black-logo-En-GB-1019 - Copy Thumb_mark-of-trust-certified-ISOIEC-27001-information-security-management-white-logo-En-GB-1019 - Copy

 

security_compliance-and-certification
europe

Europe

Primary systems are hosted in availability zone EU-WEST–2. Secondary/Backup Systems are hosted in availability zone EU-WEST–1.
usa

United States

Primary systems are hosted in availability zone US-EAST–2. Secondary/Backup Systems are hosted in availability zone US-EAST–1.
client-specific

Client-specific hosting requirements

If you have specific hosting needs that are unique to your organisation, we can find an appropriate solution for your needs.

Data protection

Compliance

Opus 2 Services and Agreements meet global legal and regulatory requirements, including but not limited to:

  • General Data Protection Regulation (GDPR)
  • UK GDPR
  • California Consumer Privacy Act (CCPA)
  • Singapore Personal Data Protection Act
  • Australian Privacy Act
  • Canada Federal Personal Information Protection and Electronic Documents Act

Authentication and authorisation

There are several authentication methods in place to increase the security of accounts. This includes a client-defined password policy and several options for multi-factor authentication. It is also possible to link to your Single Sign-On provider to centralise account control and authentication policies.

User management

As a client, you have full control over the permissions for each user you register to the platform. You can create, modify, and remove users based on your own internal policies.

Encryption at rest

All customer data is hosted on encrypted AWS containers. Encryption keys are programmatically managed through the AWS Key Management System (KMS).

Encryption in transit

All internet-facing application instances are assigned a TLS certificate to ensure that data communicated between your computer and the Opus 2 infrastructure is encrypted using the latest encryption protocols. The certificate is generated through a secure process and only supports encryption protocols and ciphers that are not currently known to be broken or otherwise compromised. All components communicate with each other over TLS.

Incident response

The Opus 2 ecosystem includes 24/7 security monitoring. Every device, server instance, and application provide a rich set of data points into our centralised log aggregation platform. Using advanced AI, this data is continuously analysed for anomalies and any events that potentially indicate a security incident are investigated by the Opus 2 Incident Response team.
incident_response

Third parties

Apart from AWS, we do not rely on any third parties to provide our solutions and services to our clients. Where third parties are involved for additional services, security screening is undertaken, and an NDA is signed. We also conduct the same level of background checks for our own employees, and we sign a Data Protection Agreement (DPA), as required by the GDPR. 
We work with independent court reporters who are considered third parties for the services they provide. Each court reporter receives Opus 2’s Employee Security Awareness Training and signs an NDA with Opus 2. Additionally,several of the court reporters hold security clearances of varying levels for which they have undergone independent background checks. The court reporters are contractually obliged to maintain the security of client information in line with Opus 2’s security classification and data protection policies.
security_third_parties

Meet our dedicated security team 

Our core information security team consists of security experts who work with the wider Opus 2 team, from Human Resources to Software Engineering and from Finance to Support, to deliver our solutions and services to you as securely as possible.
Anderson Sidwell
Anderson Sidwell
IT Director
Madiha
Madiha Assim
Security Engineer
CTA block sg
CTA block sg mobile

Ready for your next step?