Ossus logo

Ossus

Last updated Jun 26, 2026

Security and trust at Ossus

Intelligence for cultural institutions.

Ossus builds intelligence systems for libraries and cultural institutions. Cultural institutions hold public trust: they serve students, researchers, families, and communities, often with sensitive information about what people read, study, and wonder.

We design Ossus with that responsibility in mind. Our systems are built to help institutions understand and manage their collections without compromising patron privacy.

ISO 27001
SOC 2
135
controls
27
resources
235
subprocessors

Compliance

2

Independently audited and continuously evidenced against the standards our customers rely on.

ISO 27001
In progress

ISO 27001

ISO/IEC 27001:2022

Valid through
Jun 26, 2027
SOC 2
In progress

SOC 2

AICPA Trust Service Principles Service Organization Controls (SOC)

Valid through
Jun 26, 2027

Controls

135

The safeguards we operate across our organization, technology, people, and facilities.

Inventory Management

Asset Management

Organization maintains an inventory of information systems, which is reconciled on a periodic basis.

Reviewed Jan 24, 2026SOC 2

Inventory Management: Applications

Asset Management

Organization maintains an inventory of application assets, which is reconciled on a periodic basis.

Reviewed Jan 25, 2026SOC 2

Inventory Labels

Asset Management

Organization assets are labeled and have designated owners.

Reviewed Jan 24, 2026ISO 27001SOC 2

Media Marking

Asset Management

Where applicable, Organization marks information system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information. Exemptions must be approved by management and remain in a specific controlled area.

Reviewed Jan 24, 2026ISO 27001

Asset Transportation Authorization

Asset Management

Organization authorizes and records the entry and exit of systems at datacenter locations.

Reviewed Jan 24, 2026ISO 27001SOC 2

Maintenance of Assets

Asset Management

Equipment maintenance is documented and approved according to management requirements.

Reviewed Jan 24, 2026ISO 27001SOC 2

Business Continuity Plan

Business Continuity

Organization's business contingency plan is periodically reviewed, approved by management and communicated to relevant team members.

Reviewed Jan 24, 2026SOC 2

Continuity Testing

Business Continuity

Organization performs business contingency and disaster recovery tests on a periodic basis and ensures the following: • tests are executed with relevant contingency teams • test results are documented • corrective actions are taken for exceptions noted • plans are updated based on results

Reviewed Jan 24, 2026ISO 27001SOC 2

Resources

27

Policies, documentation, and reports that govern how we protect customer data.

Code of Business Conduct

Version 2026.3 · Reviewed Jun 25, 2026 · yearly

Customer Service Agreement Security Addendum

Version 2026.2 · Reviewed May 5, 2026 · yearly

Security Compliance Reporting Procedure

Version 2026.2 · Reviewed May 17, 2026 · yearly

System Description

Version 2026.4 · Reviewed May 5, 2026 · yearly

Control Environment & Governance

Version 2026.4 · Reviewed May 5, 2026 · yearly

Asset Management & Data Classification Policy

Version 2026.5 · Reviewed Jun 25, 2026 · yearly

Change Management Policy

Version 2026.5 · Reviewed Jun 25, 2026 · yearly

Third-Party Risk & Vendor Management Policy

Version 2026.4 · Reviewed May 5, 2026 · yearly

Subprocessors

235

Third-party providers that process customer data on our behalf, and where they operate.

WorkOS

Software as a Service

OAuth app authorized by users

Website

edclub

Software as a Service

OAuth app authorized by users

Website

User Interviews

Software as a Service

OAuth app authorized by users

Website

Meet for Workspace Studio

Software as a Service

OAuth app authorized by users

Website

doris

Software as a Service

OAuth app authorized by users

Website

ITVX

Software as a Service

OAuth app authorized by users

Website

coldcake

Software as a Service

OAuth app authorized by users

Website

Granted

Software as a Service

OAuth app authorized by users

Website

Questions about our security?

We're glad to help your security and procurement teams move quickly.