Security Addendum
This Security Addendum is incorporated into and made a part of the written agreement between Optima Engineering LLC ("Optima") and Customer that references it, including the Master Cloud Services Agreement (the "Agreement"). Capitalized terms not defined in this Security Addendum have the meanings given in the Agreement. If this Security Addendum conflicts with the Agreement, the Agreement governs.
Optima maintains the administrative and technical safeguards described below, which are designed to protect the Services and Customer Data (the "Security Measures"). Optima may update this Security Addendum from time to time, provided that updates do not materially diminish the protection the Security Measures give Customer Data.
1. Deployment and Shared Responsibility
The Services are provided either as a managed service operated by Optima in its own cloud account or as a deployment in Customer's own cloud subscription, as stated in the Order Form. In both models, each customer has a dedicated deployment with its own database and secret store. Physical security of the underlying data centers is provided by the cloud infrastructure providers listed on our Subprocessors page.
Shared Optima services relay requests to third-party model providers when Customer uses models made available by Optima, and relay events from connected source-control systems. These shared services do not store Customer Content.
Security is a shared responsibility. Optima is responsible for the security of the Platform software and of the infrastructure Optima operates. Customer is responsible for:
- its Authorized Users' accounts and credentials, including the single sign-on and multi-factor authentication settings of its identity provider;
- the roles and permissions it grants within the Platform;
- the configuration of its Agents, including guardrails, approval thresholds, and the data and systems it connects to them;
- credentials for the third-party services it connects, including its own model provider accounts; and
- where the Services are deployed in Customer's own cloud subscription, the security of that subscription and of the network access rules Customer controls.
Where the Services are deployed in Customer's own cloud subscription, Optima retains the administrative access to the deployment that it needs to operate, support, and update the Services.
2. Encryption
- In transit: Optima uses TLS 1.2 or better for Customer Data in transit to and from the Services over untrusted networks.
- At rest: Customer Data is encrypted at rest using the storage encryption of the cloud infrastructure provider.
3. Network and System Security
- Network controls: inbound network access to each deployment is restricted to the Platform's edge, and databases are not reachable from the public internet.
- Infrastructure and releases: infrastructure is defined in version-controlled templates and scripts, and application releases are built and cryptographically signed by an automated pipeline.
- Dependency scanning: software dependencies are automatically checked for known vulnerabilities on every code change, and for available updates every week.
- Security assessments: Optima performs regular internal security assessments and vulnerability testing.
4. Access Controls
- Least privilege: Optima grants its personnel access to systems and Customer Data based on job function and limits it to the minimum needed.
- Multi-factor authentication: MFA is required for all Optima personnel access to production systems and administrative tools.
- Access reviews: access permissions are reviewed periodically and revoked promptly on role changes or offboarding.
- Access to Customer Data: Optima personnel access Customer Data only as necessary to provide the Services under the Agreement or to comply with Law.
- Training: Optima personnel receive security awareness training.
5. Platform Security Features
The Platform gives Customer the following controls over its Agents:
- Agent isolation: in production deployments, each Agent run executes in an isolated sandbox with fixed compute limits and restricted network egress.
- Guardrails: the Platform enforces the policies and guardrails Customer configures for its Agents.
- Human oversight: Customer can require human approval for Agent actions and can halt Agents with a kill switch.
- Access management: the Platform supports role-based access control and single sign-on for Authorized Users.
- Audit log: the Platform records the governance decisions it makes about Agent actions in an audit log.
6. Incident Response
- Notification: Optima notifies Customer of a Security Incident without undue delay, and no later than seventy-two (72) hours after becoming aware of it, as set out in the Agreement.
- Post-incident analysis: after a security incident, Optima performs a root cause analysis and implements corrective measures.
7. Data Handling
- Retention and deletion: Customer Data is retained and deleted as set out in the Agreement and the Data Processing Agreement.
- No model training without consent: Optima does not use Customer Content or Outputs to train, fine-tune, or improve its machine learning models without Customer's prior written consent (Section 5.5 of the Master Cloud Services Agreement).
- Backups: backup and recovery commitments, if any, are stated in the Order Form.
8. Assurance
- Audits: Customer's audit rights are set out in the Agreement.
- Certifications: compliance certifications and audit reports, as they become available, are provided to customers on request, subject to confidentiality.
- Subprocessors: Optima maintains a current list of subprocessors and gives advance notice before engaging new ones, as set out in the Agreement.
9. Reporting Vulnerabilities
If you discover a potential security vulnerability, please report it responsibly to security@optima.engineering. Optima will acknowledge receipt within two business days and work to investigate and address confirmed vulnerabilities promptly.
For questions about this Security Addendum, contact security@optima.engineering. Additional security commitments, if any, are stated in the Order Form.