Optro

Optro

Search the Trust Center...
Ctrl +K

Optro | Trust Center

Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.


Our Philosophy

In order to protect our customers and their data, Optro has adopted a formal information security management program that governs software development, infrastructure operation, administration, and delivery of the Optro product application.

Optro maintains an ISO 27001-certified information security program, along with an extensive control environment that is aligned with and regularly assessed against industry standard frameworks such as NIST 800-53, SSAE-18 SOC 2, Cloud Security Alliance STAR, and HIPAA. The Optro application is hosted exclusively on cloud infrastructure that meets FedRAMP moderate impact compliance requirements.

John Volles

Director - Security, Privacy, and Trust

Coming Soon

Optro will be updating the domain of our Trust Center in the coming weeks to reflect the recent name change from AuditBoard to Optro. Please see the Trust Center announcement below for additional info


Badges

ccpa
CCPA
gdpr
GDPR
hecvat
HECVAT
csa
CSA
hipaa
HIPAA
iso-27001
ISO 27001
vpat
VPAT

Featured Documents


Trusted by

NVIDIA
Cisco
Uber
Snowflake
stripe.com
Humana

Documents & Knowledge Base FAQs


Announcements

Optro Acquires Midship!

We have an exciting update to share. Optro recently acquired Midship, a pioneer in AI-native automation for SOX compliance, and we wanted to make sure you had the full picture from a security and compliance standpoint.

Midship's agentic technology is being offered as a new offering that will integrate closely with Optro's Controls Management solution, enabling teams to automate the most time-consuming parts of SOX and controls testing — from ingesting raw, unstructured evidence to generating audit-ready workpapers. If you're interested in learning more about how these capabilities could benefit your team, please reach out to your account representative.

For existing Optro customers, the Midship integration will not result in any changes to your current platform experience or architecture.

Midship's SOC 2 Type II report is now available in the Optro Trust Center (trust.optro.ai). The examination covered October 25, 2025 through January 25, 2026 and returned an unqualified opinion with no exceptions noted. We are working to bring Midship into the scope of Optro's annual audit reports, expected near year-end.

Questions? Reach us at customer-assurance@optro.ai

Thank you for your continued trust in Optro.

  • The Optro Security Team

Axios Supply Chain Attack - No Impact to Optro

Optro is not affected by this incident.

The compromised versions (axios@1.14.1 and axios@0.30.4) were never present in our codebase, container images, or deployed environments. We confirmed this through a full SBOM analysis against our Ox Security inventory within hours of disclosure.

Specifically:

  • No Optro repository contains either compromised axios version
  • The malicious phantom dependency (plain-crypto-js) does not appear anywhere in our dependency tree
  • Our CI/CD pipelines use lockfile-pinned installs, which prevent automatic resolution to newly published versions
  • On top of this, we automatically block malicious packages, including the relevant axios and plain-crypto-js packages from ever being committed.
  • We proactively blocked the attacker's C2 infrastructure (142.11.206.73 / sfrclak.com) at the network level as a precautionary measure

Should you have any further questions, please reach out to customer-assurance@optro.ai


AuditBoard is now Optro — A New Chapter in GRC

We are excited to share a significant milestone in our company’s journey. Today, AuditBoard has officially rebranded as Optro.
Since our founding, we have been committed to helping our customers transform risk into opportunity. As we enter a new era of Governance, Risk, and Compliance (GRC) powered by agentic AI, our new identity as Optro reflects our evolution into a single, coherent system of action for modern risk practitioners.

What This Means for You
While our name and look have changed, our commitment to the security, privacy, and success of our customer community remains our top priority.
No Action Required: There are no immediate changes required for your current login credentials or platform access.
Security & Compliance: Our underlying security controls, compliance certifications (including SOC 2 and ISO), and data protection practices remain exactly the same. The legal entity and your existing contracts are not affected by this brand name change.

Upcoming Trust Center Domain Update
To align with our new brand, we will be updating our Trust Center domain name in the coming weeks (e.g., moving from auditboard.com to optro.ai).
What to expect:
We will provide a specific date for the domain transition soon.

Once the change occurs, automatic redirects will be in place to ensure all existing links to our security documentation and reports continue to function seamlessly. Thank you for being a valued partner as we take this next step as Optro. If you have any questions regarding this transition, please reach out to your Account Manager or contact our support team.

To learn more about the vision behind Optro, you can read our full announcement here:

Thank you,
Optro Security


AuditBoard 2025 SOC1, SOC2, and HIPAA Reports Now Available!

AuditBoard is pleased to announce that our latest SOC 1 Type 2, SOC2 Type 2, and HIPAA Type 1 reports are now available within our Trust Center.

AuditBoard’s commitment to produce annual attest materials demonstrates our commitment to maintaining a robust security posture, protect our customers’ data, and meet the stringent requirements set forth by the American Institute of Certified Public Accountants (AICPA) and additional standards.

We’ve made a number of significant improvements and updates to the reports, most notably expanding the SOC2 report to cover all Trust Services Criteria. Additional items to look out for are detailed below.

Updates in 2025 Materials:

  • Inclusion of the four additional Trust Services Criteria (Availability, Processing Integrity, Confidentiality, Privacy)
  • Enhancements and updates to the System Description section to reflect the additional Trust Services Criteria now in scope
  • Updated architecture diagrams to depict our implementation of AuditBoard’s next-generation dashboards + reporting capabilities
  • Details on organizational changes over the past year including executive leadership and recent acquisition activity

Accessing the Report

You can access AuditBoard’s SOC reports directly from our Trust Center: https://trust.auditboard.com/

Thank you for continuing to place your trust in AuditBoard. Safeguarding our customers is our top priority. We encourage you to review the report and should you have any questions, please do not hesitate to contact customer-assurance@auditboard.com.


Salesloft Drift Incident: AuditBoard’s Response

AuditBoard was recently made aware of an incident involving the common Salesforce integration, Salesloft’s Drift, allowing malicious actors to obtain OAuth tokens via the integration which can potentially lead to data exfiltration from the primary Salesforce instance.

AuditBoard does not use the affected integrations and our security engineers have performed a comprehensive review of our logging and monitoring infrastructure and have not identified any indicators of compromise present within our environments. Furthermore, AuditBoard has worked with its Subprocessors, and has not identified any impact within our product supply chain at this time.

We will continue to monitor the situation and post any updates to our Trust Center (https://trust.auditboard.com/) as appropriate. If you have any questions or concerns, please do not hesitate to reach out to customer-assurance@auditboard.com.

Regards,

The AuditBoard Information Security Team


SharePoint CVEs - AuditBoard is not impacted

Following the reporting of CVE-2025-53770 and CVE-2025-49706, AuditBoard conducted an assessment to determine potential impact. AuditBoard does not use the affected technologies and is not impacted. Do not hesitate to reach out to customer-assurance@auditboard.com with any further questions.

Regards,
AuditBoard Security


Powered by Conveyor, the first end-to-end customer trust platform.
Learn more