Security

Enterprise Class Security Features

OCA certified copilots and technology partners are compliant with high level of security qualifications.

The OCA is committed to building trust in the adoption of AI copilots across industrial environments. OCA certification ensures that technology partners and their copilots meet rigorous standards for security, compliance, data integrity, and operational reliability, giving organizations confidence to deploy AI copilots at scale.

Security and Compliance

OCA-certified copilots are developed with security at their core, incorporating modern practices to protect your data, systems, and workforce.

Penetration testing & ethical hacking

Regular testing is conducted by third parties to identify and remediate vulnerabilities.

End-to-end encryption

All data is encrypted both in transit (SSL) and at rest

SOC 2 Type II compliance

Certification is currently in progress, with partners demonstrating adherence to high standards for security, availability, and confidentiality.

EU regulations compliance

Certified copilots follow GDPR and other relevant EU regulations, ensuring lawful, transparent, and purpose-limited data use.

Data Ownership and Usage

OCA-certified partners operate under a clear and strict data ownership model

You own your data

All telemetry, operational data, and interactions remain the property of your organization

Data use transparency

Certified copilots provide clear documentation on how your data is processed and stored

AI training control

Your data is not used to train shared AI models.

Granular access controls

Organizations have full control over who can access, view, or manage copilot content, ensuring sensitive information is only available to authorized users.

Protection of Private & Sensitive Information

Industrial copilots operate in high-stakes environments. OCA certification ensures private materials remain private.

Private corporate resources

such as manuals, procedures, and configurations are protected and isolated from external access

Site-specific trade secrets

Access to proprietary information and processes is strictly limited to authorized users.

Enterprise-Grade Hosting & Deployment Options

Certified copilots support flexible, secure, and scalable deployment compatible with existing enterprise systems, including corporate SSO

Hosted on Microsoft Azure

Including options for global availability and regional compliance

Redundant systems

ensure high availability and business continuity

Enterprise Single Sign-On (SSO)

Full integration for secure, seamless user access

Private hosting options

Available upon request for organizations with on-premise or air-gapped requirements

Join The Open Copilot Association

Stay Up To Date On The Latest Innovations & Events