Security & Trust
What's actually true today.
We're a young company. Rather than a padded compliance-checklist page, here's a plain account of how your data and payments are actually handled by this site right now — and what we're working toward.
Data handling
Olympia's marketing site (the one you're on right now) is a static HTML/JS site. There is no Olympia-operated application server and no first-party database sitting behind it.
- Forms. Lead-capture, migration, SaaS-cost-reduction, custom-software, location-request, and contact forms all submit to a single third-party form-backend service (Formspree or similar) — not to any database we run ourselves.
- Analytics. We use Plausible, a cookieless analytics tool that doesn't track you across sites or build an individual profile of you. It records aggregate events (a page view, a calculator interaction, a form submit) — nothing that identifies you personally.
- No first-party database. We don't store your name, email, or usage history on infrastructure we control. The third-party services named on this page — the form backend, Plausible, and Stripe — are the only places your submitted information lives.
This is consistent with, and described in more detail on, our Privacy Policy.
Payment security
VPS tier checkout runs through Stripe. When you check out (via Stripe Checkout, opened from the configurator), you enter your card details directly on Stripe's own hosted checkout page — not on an Olympia-controlled page or server.
Olympia never sees, receives, or stores your full card number, CVC, or other card data at any point. Stripe is a payment processor used by a large share of the internet's checkout flows and handles that data under its own PCI-compliant infrastructure — we're relying on Stripe's security, not building our own.
Infrastructure
Olympia's VPS and dedicated-server tiers are priced against Hetzner-equivalent specs (see our comparison page) — the underlying hardware is comparable to what a well-run European VPS provider offers, not a proprietary in-house data center.
We do not currently hold any third-party compliance certification — no SOC 2, no ISO 27001, no completed penetration test. We're not going to claim one we don't have. If and when we pursue one, we'll say so here with a real date and a real report, not before.
What we're working toward
- Automated infrastructure monitoring and a live status page. We provision servers today, but we don't monitor them automatically yet — Status says exactly what that means.
- A documented incident-response process, published here once it's written down rather than described from memory.
- Third-party security review, once the business is at a stage where that's a meaningful investment rather than a checkbox.
We'd rather tell you honestly where we are than dress up a young company with enterprise security theater.
Report a security concern
Found a vulnerability, a data-exposure issue, or anything else security-related? We want to hear about it directly, before it goes anywhere else. Email security@olympia.so with details, and we'll respond as quickly as we can. We don't yet have a formal bug-bounty program or a published PGP key — if that changes, this page will say so.