o22

Security

o22 is built for teams that need production-grade controls around agents, knowledge, and model credentials — without overstating compliance status.

Current posture

  • Tenant isolation via organization-scoped data access and API headers
  • Encrypted storage for integration secrets (AES-256-GCM)
  • Audit logging for sensitive administrative and billing actions
  • Session auth via better-auth with optional two-factor support

SOC 2 readiness

SOC 2 Type II readiness work is in progress. We do not currently claim SOC 2 certification or display certification badges. We will update this page when an independent report is available.

Responsible disclosure

Report suspected vulnerabilities to security@o22.ai. Please avoid testing against production customer data without prior written authorization.