# Security

> What Otto does for a security reader: the controls and the mechanism behind each, and the audit status said plainly — SOC 2 Type II and ISO 27001 in audit, not certified.

- Source: https://ottoforfirms.com/trust/
- Publisher: Otto — https://ottoforfirms.com
- Updated: 2026-09-01

# Join the future. Bring the evidence.

Your firm wants what AI makes possible. Your examiner wants evidence — Otto is built to hand it over.

## Nothing to patch.

There is no server anyone can neglect — no VM, no container, no SSH. The runtime is Cloudflare's.

*Static assets + Workers · TLS 1.2 floor · HSTS preload*

## The gate can't be talked into anything.

The part that blocks a call is a rule, not a model. Deterministic — and it shows its work.

*Consent, quiet hours, frequency & SCRA holds, checked before the dial · every block recorded*

## Transcripts expire. On schedule.

Call records sweep at 90 days. Consent records outlive them on purpose — TCPA claims run four years.

*90-day sweep · consent records retained 1,600 days*

## Your archive never leaves the building.

Otto Redact swaps identifiers for tokens on your own hardware. The model reasons about [SSN-1]; only your screen resolves it.

*On-device tokenization · the reversible map stays with you*

## One door, and we watch it.

The site answers on a single origin, and the security contact reaches a real inbox.

*workers.dev off · security.txt (RFC 9116) · Entra sign-in with MFA*

## In audit. Said plainly.

When a report issues, this page will say so — and not a day before.

- **SOC 2 Type II** — In audit
- **ISO 27001** — In audit
- **PCI DSS** — Out of scope — card data never enters Otto

## For your diligence team.

The full control inventory is written to be handed to an auditor — ask via https://ottoforfirms.com/contact/. The public half
you can check yourself: `dig TXT _dmarc.ottoforfirms.com`, `dig DS ottoforfirms.com`,
`curl https://ottoforfirms.com/.well-known/security.txt`.

Read next:

- [The bank third-party-risk questionnaire, question by question](https://ottoforfirms.com/guides/bank-third-party-risk-questionnaire/)
- [What a collections firm's audit file should contain](https://ottoforfirms.com/guides/the-audit-file/)
- [The data processing addendum](https://ottoforfirms.com/#/legal/dpa)

Otto is a technology provider, not a law firm: these are controls, and whether they satisfy an obligation is
your counsel's call, not ours. The compliance engine ships all fifty states, configured; the demo shows four of
them in end-to-end depth.

## About Otto

These pages describe what Otto does. The quickest way to judge them is against your own files.

- [Book a demo](https://ottoforfirms.com/contact/)
- [See what it costs](https://ottoforfirms.com/pricing/)

---

This page describes Otto, not the law, and is not legal advice. Otto applies rules that have been written down correctly; it does not warrant that using it results in compliance with any statute, regulation or contract. Where a rule is named here, confirm it against the primary source and your own counsel before relying on it.
