Security built for firms that can't afford a breach.

Client conversations are among the most sensitive information a firm holds. Here is exactly how Iris protects them, stated in plain terms, with nothing glossed over.

On this pageThe postureWhat each control meansVerificationReporting a vulnerability

Four commitments, no asterisks. Each one is described in full below.

The posture, in plain terms.

TLS 1.3

Everything in transit, visitor conversations, dashboard, alerts.

AES-256

Everything at rest, transcripts, summaries, account data.

Isolated

Each firm's data in its own silo. No cross-firm access, ever.

90 days

Default retention, configurable, and deletable on request.

What each control means.

Encryption in transitEvery connection travels over TLS 1.3, including a visitor's conversation, the firm dashboard, and email alerts. Nothing readable crosses the open internet.
Encryption at restConversations, summaries, and account data are stored encrypted with AES-256. A compromised disk yields ciphertext.
Access controlFirm data lives in per-firm silos; no firm can access another's conversations, and no setting changes that. Internal access is role-based, logged, and granted only to the engineers resolving a specific issue.
HostingUS-based infrastructure. Data does not leave US regions, and neither do the backups.
RetentionConversation transcripts default to 90 days and are configurable per firm. Any firm can request deletion at any time. Deletion is permanent, completed within 30 days.

Verification, honestly stated.

We don't put a badge on this page. This page describes the controls in place, and we share current security documentation with firms that ask.

If you found something, tell us.

We treat outside scrutiny as a contribution, not a threat. Vulnerabilities in the Iris widget, the dashboard, or this site can be reported to security@oculonsystems.com, acknowledged within two business days, with the full commitments on the disclosure page.

Questions about security?

The confidentiality commitments, who owns what, and what we never do with it, are one click away. For anything else, write to the security team directly; a person reads it.