Skip to content
📣 Celebrating 13 Years of Innovation, trust, and excellence.
Security

How we handle your data, stated plainly.

What we encrypt, who can reach client information, where it is stored, and how to tell us if you find a problem.

Our position

We place engineers inside client systems and we run managed services on client infrastructure, so the honest answer to most security questions is that your controls govern your estate and ours govern ours. This page covers ours.

Where we hold a certification we say so. Where we do not, we say that too, further down this page. A security page that only lists strengths is not useful to anyone evaluating a supplier, and the gaps are the part you would find in diligence anyway.

How data is protected.

  • Encrypted in transit

    Every connection to this site and its APIs is HTTPS. Strict-Transport-Security is set for two years with subdomains included and preload requested, so browsers refuse to fall back to an unencrypted connection.

  • Encrypted at rest

    Application data is held in Amazon DynamoDB and Amazon S3, both of which encrypt stored data by default using AWS-managed keys.

  • Hardened responses

    The site sets X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy on every response, which closes off clickjacking, MIME sniffing, referrer leakage and unrequested access to camera, microphone, location and payment APIs.

  • No credentials in the browser

    AWS credentials and table names are read on the server only. The client bundle is checked to ensure the AWS SDK never ships to the browser.

Who can reach client data.

  • No public sign-up

    There is no self-service registration. Every account is created by an administrator who sets the person's role at the point of invitation.

  • Four roles, least privilege

    Accounts are Admin, HR, Recruiter or Sales. A person authenticated but not placed in a staff group has no access at all rather than a default level of it.

  • Managed authentication

    Sign-in runs through Amazon Cognito. Passwords are never stored by this application, and a new joiner must set their own password on first sign-in before they can reach anything.

  • Access ends with the engagement

    Accounts are removed by an administrator when someone leaves the company or rolls off an account.

Where data lives, and who reaches it.

Application data is stored and processed in Amazon Web Services in the US East (Ohio) region, us-east-2.

We operate delivery centres in India and the United Kingdom, and named personnel in those locations can access client data where their role on an engagement requires it. Access follows the same role model as everyone else, and the scope of it is agreed in the Master Service Agreement before work starts.

If your programme requires US-only personnel or data handling, say so during scoping. It is a constraint we can staff to, but it has to be agreed up front rather than assumed.

Certifications we hold.

These are supplier-diversity certifications. They speak to ownership and procurement eligibility, not to information security, and we do not present them as security credentials.

  • NMSDC
  • Ohio WBE
  • Ohio MBE
  • City of Columbus MBE

What we do not hold

Ocean Blue is not SOC 2 audited and does not hold ISO 27001. We have not commissioned a third-party penetration test. If your procurement process requires either, tell us early and we will tell you honestly whether we can meet the timeline rather than let it surface late in the process.

Reporting a vulnerability.

If you have found a security problem in this site or any Ocean Blue system, email hr@oceanbluecorp.com with “Security report” in the subject line.

Include what you found, where, and the steps to reproduce it. We will confirm receipt and keep you updated as we work through it. We ask that you give us a reasonable window to fix the issue before publishing it, and that you avoid accessing or altering data that is not your own while testing.

We do not run a paid bug bounty. We will credit you if you would like to be named.

Incident history

We have not disclosed a security incident affecting client or candidate data. If that changes, the incident and its resolution will be recorded here with dates.

For live availability of the AWS services this product runs on, see the status page.

An Ocean Blue security review

Send us your security questionnaire.

We would rather answer it early and tell you where we fall short than discover the mismatch after a contract is drafted.