Trust

Security & compliance

Everything on this page is something we can point at in our own infrastructure. Where we don’t have something a buyer might expect, we say so rather than leaving it out.

How to read this page

Plenty of trust pages imply certifications they don’t hold. This one separates what we run today from what we don’t have yet, because the second list is the one that decides whether we waste your time.

Last reviewed 12 August 2026.

Where your data lives

OKR Studio runs entirely on Microsoft Azure inside the European Union. There is no US region and no option to move your data outside the EU.

  • Application, database, and file storage run in Azure West Europe.
  • AI features run on Azure OpenAI Service in Sweden Central, which is also inside the EU.
  • Transactional email is delivered through Azure Communication Services with an EU data location.
  • Backups and geo-redundant storage stay within EU-paired Azure regions.

Encryption

Every connection to OKR Studio is encrypted, and stored data is protected by Azure platform-managed encryption.

  • All traffic is HTTPS. TLS 1.2 is enforced as the minimum across the database, storage, application, and background services.
  • HTTP Strict Transport Security is set for one year including subdomains, alongside a Content Security Policy, X-Frame-Options: DENY, and X-Content-Type-Options: nosniff.
  • Database connections are encrypted with certificate validation enabled.
  • Data at rest is protected by Azure SQL Transparent Data Encryption and Azure Storage Service Encryption.
  • Session cookies are HttpOnly and Secure.

Authentication and access

You can sign in with an email and password or through an identity provider, and you can require two-factor authentication for everyone in your organization.

  • Single sign-on with Microsoft Entra ID, Google, or GitHub, implemented over OIDC.
  • Time-based one-time password (TOTP) two-factor authentication, compatible with any standard authenticator app.
  • Administrators can require MFA across the entire organization, not just per user.
  • Role-based access control with four roles — Admin, Product Leader, Team Member, and Stakeholder — enforced on every create, update, and delete action.

How organizations are kept separate

OKR Studio is a multi-tenant application. We think you should know exactly how that separation is implemented rather than being told it is simply secure.

  • Every authenticated request carries an organization identifier, which is validated server-side before any record is returned or modified.
  • Database access runs through parameterized stored procedures that take the organization as an explicit parameter, so queries cannot return another tenant's rows.
  • Ownership and permission checks run as separate layers on top of that organization scoping.
  • To be precise: this is application-layer isolation on a shared database schema. We do not use per-tenant databases or SQL Server row-level security.

Your data, and getting it back

You own your data. We have built the export and deletion paths that GDPR requires, and they work without you having to email anyone.

  • One-click export of everything we hold about a user, in machine-readable JSON.
  • Account deletion removes access and anonymizes personal information.
  • We do not sell your data, and we do not share it with third parties for their own purposes.
  • Our sub-processors are published and kept current.

How AI features handle your content

AI is opt-in. If your organization does not want its content sent to a model, an administrator can turn the features off.

  • AI requests are processed by Azure OpenAI Service within the EU.
  • Your content is not used to train foundation models.
  • AI features require explicit consent before first use, and AI-generated content is labelled as AI-assisted in the product.
  • The deterministic parts of the product — progress, pace, and at-risk calculations — are computed by us, not by a model.

What we don’t have yet

If any of these is a hard requirement for your organization, tell us at the start of the conversation. We would rather lose the deal early than fail your review late.

SOC 2 Type II and ISO 27001

We do not hold either certification today. Our infrastructure runs on Azure, which does hold them, but inheriting a provider's certification is not the same as holding your own and we will not describe it as though it were.

SAML and SCIM provisioning

We support Microsoft Entra ID over OIDC, which covers sign-in but not directory-driven provisioning. If your organization mandates SAML or SCIM, we do not meet that requirement yet.

Customer-facing audit log export

There is no self-serve audit log for administrators to export today.

Non-EU data residency

There is no US or APAC region. If your organization requires data to stay outside the EU, we are not a fit.

A contractual uptime SLA

We do not publish a standing SLA. Uptime commitments can be discussed as part of an Enterprise contract.

Frequently asked questions

Where is OKR Studio data stored?

All customer data is stored and processed within the European Union. The application, database, and file storage run in Microsoft Azure West Europe, AI processing runs on Azure OpenAI Service in Sweden Central, and transactional email is sent through Azure Communication Services with an EU data location. There is no non-EU region.

Is OKR Studio SOC 2 or ISO 27001 certified?

No. OKR Studio does not currently hold a SOC 2 Type II or ISO 27001 certification. Our underlying infrastructure provider, Microsoft Azure, holds both, but we do not present that as our own certification. If your procurement process requires a certified vendor, we would rather you know now than discover it partway through a security review.

Does OKR Studio support SAML or SCIM?

Not today. We support single sign-on with Microsoft Entra ID, Google, and GitHub over OIDC, and organization-wide enforcement of TOTP two-factor authentication. SAML federation and SCIM user provisioning are not implemented.

How is my organization's data kept separate from other customers?

Every authenticated request carries an organization identifier that is validated server-side before any record is read or written, and all database access runs through parameterized stored procedures scoped to that organization. This is application-layer isolation on a shared schema — we do not use per-tenant databases or SQL Server row-level security.

Is my data used to train AI models?

No. AI features run on Azure OpenAI Service inside the EU, and your content is not used to train foundation models. AI features are opt-in and require explicit consent, and an administrator can disable them for the whole organization.

Can I get a DPA or complete a security questionnaire?

Yes. Email support@okrstud.io and we will send a Data Processing Agreement or work through your security questionnaire. We will answer it accurately, including where the answer is no.

Running a vendor review?

Email support@okrstud.io for a Data Processing Agreement or to send us your security questionnaire.