Security & Data
OaaS handles sensitive alarm and contact data on behalf of your monitoring centre. Here is exactly how that data is protected, isolated, audited, and — when you need it — deleted.
Core Architecture
Every connection to OaaS uses TLS — no personal data travels unencrypted. Disk-level encryption is enabled on all servers. Passwords and verification PINs are stored as one-way cryptographic hashes, never in plain text.
Each monitoring centre's data lives in its own isolated database. There is no SQL query path that joins one customer's data to another's. The application enforces company context on every single request. Dedicated servers available.
Every meaningful action — logins, configuration changes, activations processed, manual overrides, plan edits — is recorded in a hash-chained audit log. Admins can search, filter, and export at any time from the admin panel.
When an alarm triggers, only the ticket ID is sent to OaaS. OaaS fetches what it needs from your CMS via a secure, token-based REST API — sensitive details are never pushed to us unsolicited.
Staff can only access what their role permits. All staff access to customer data is logged in the audit trail. You authorise every user on your side, scoped by role — and nobody outside your organisation sees your data.
Dedicated Linux servers with firewalled access, signed inter-service communication, regular security updates, and containerised deployment. Hosted in Sydney, Australia — with alternative regions available on request.
Contact Verification
OaaS supports per-contact PINs or verification codes that the contact must confirm before any activation details are disclosed. This protects your alarm data even if the wrong person answers a call.
The PIN is derived from the contact's data already held in your CMS — you don't need to maintain a second credential set. Failed verification is logged, the channel attempt is treated as unanswered, and OaaS falls through to the next contact per your plan.
A standard alternate verification that lets a contact confirm they are safe. Accepted on all channels exactly like a normal PIN — no visible difference to anyone observing.
A covert alternate that looks identical to a successful verification — the contact sees no behavioural difference. Behind the scenes OaaS silently logs an AUDIT_SECURITY event, posts a DURESS note to the CMS, and escalates to the operator queue. No log or transcript ever names which credential matched.
High-Security Profile
For customers with strict data-minimisation requirements, OaaS offers a per-company High-Security data-handling profile. Standard customers are unaffected. When enabled, OaaS automatically pseudonymises all identifying data shortly after each activation closes.
Your CMS remains the authoritative record. Because OaaS re-fetches account data from the CMS on each new alarm, de-identification does not affect service quality. Pseudonymisation is one-way — once applied, original values cannot be recovered from OaaS.
Data Retention
Retention periods are configurable per company. You can set data to be retained for years, months, weeks — or deleted immediately after each activation closes. You can request deletion of specific data at any time.
Administrators can permanently purge all completed activation history within a chosen date range — across both the decision platform and engagement engine, including call recordings. This is a deliberate, type-to-confirm action recorded in the audit log.
Data Location
OaaS is hosted on professionally managed cloud infrastructure. Your operational database — isolated per customer — and the application run on servers in your chosen region. We can deploy in the region that suits your compliance and data residency requirements.
To place calls and send messages, content passes through the relevant carriers for your region. We can discuss specific carrier and provider arrangements during onboarding to ensure they meet your requirements.
We work with monitoring centres across Australia and New Zealand. If you have specific data handling, residency, or SLA requirements, get in touch and we'll walk through exactly how OaaS can meet them.