Security
OSCI Security Whitepaper
How OSCI Protects Customer Data and Systems
Last updated: (July 29, 2026)
OSCI Security Whitepaper download
Open Source Consulting Inc. (hereinafter “OSCI”) treats protecting the confidentiality, integrity, and availability of customer data and systems as a top priority. This whitepaper summarizes the security practices, controls, and governance structure that OSCI maintains across its people, processes, and technology. OSCI is currently undergoing SOC 2 Type II certification, and this document will continue to be updated as its compliance status evolves.
1. Governance and Compliance
● OSCI maintains a comprehensive information security program approved by its CEO, covering access control, encryption, data management, incident response, operational security, physical security, risk management, secure development, third-party (vendor) risk management, and business continuity. All policies are reviewed at least annually.
● OSCI operates a formal risk management program aligned with ISO 27005 and NIST SP 800-30/800-37, and performs risk assessments and network penetration testing at least annually.
● OSCI is currently pursuing SOC 2 Type II certification.
● All employees and contractor personnel complete security awareness training upon hire and annually thereafter, and provide written acknowledgment of OSCI's Information Security and Acceptable Use Policy (AUP).
2. Data Protection and Encryption
● Data is classified by sensitivity (e.g., Confidential, Restricted, Public), with separate handling requirements defined for each classification level.
● Data in transit is encrypted using TLS 1.2 or higher (with TLS 1.3 supported), and the use of weak protocols and cipher suites is blocked.
● Data at rest is encrypted using AES-256, with key management following NIST SP 800-57 guidelines, including restricted access and periodic key rotation.
● Company-issued devices use full-disk encryption, and backup data is also encrypted at rest.
● Secrets (such as credentials) are never hardcoded or stored in plaintext in source code; credentials entered by customers are stored encrypted and masked on screen.
● Data is retained only as long as necessary for legitimate business, legal, or contractual purposes, and is securely deleted or destroyed once the retention purpose no longer applies or upon a customer's valid deletion request.
● Data storage and processing methods may vary by service and deployment environment. Data processed in the Cloud environment is securely stored and managed within the relevant cloud infrastructure; in the Data Center environment, OSCI does not store data from apps installed in the customer's own environment.
3. Infrastructure and Operational Security
● OSCI's operating infrastructure is built on Amazon Web Services (AWS), and physical security of the data centers is managed by AWS under the shared-responsibility model.
● Networks are configured according to least-privilege and segmentation principles (network segmentation, restrictive security group rules, and least-privilege-based access and account management), blocking unnecessary access.
● Systems are continuously monitored through centralized logging, file integrity monitoring, and intrusion detection and alerting.
● Changes to production systems follow a formal change management process requiring review and approval prior to deployment.
● OSCI runs regular security vulnerability scans and a risk-based remediation process.
● Cloud services are protected by DDoS mitigation and internally defined availability targets, and company-issued devices are protected with endpoint protection, including anti-malware and email threat detection.
● The service availability targets stated in this document are targets only and should not be construed as a guarantee.
4. Access Control
● Every user is provisioned with an individual account; shared account use is prohibited.
● Multi-factor authentication (MFA) is required for access to company systems and for privileged (administrative) access to production environments.
● Access is granted based on the principle of least privilege and role-based assignment, through a formal approval process that separates the requester from the approver.
● Access rights are reviewed at least semi-annually, revoked immediately upon termination, and promptly adjusted upon role changes.
● Access to source code and production systems is restricted, logged, and periodically reviewed.
5. Secure Software Development
● OSCI maintains a formal Secure Development Lifecycle (SDLC), and all changes deployed to production must undergo peer code review.
● Development follows Secure-by-design and Privacy-by-design principles, applying coding standards informed by OWASP guidelines.
● Development, staging, and production environments are strictly separated, and real customer data is not used for testing without explicit approval and data minimization measures.
● The build pipeline includes automated security checks such as static analysis, software composition analysis (SCA), and secrets scanning.
● Identified vulnerabilities are tracked and remediated according to risk level, and development personnel complete secure coding training annually.
6. Incident Response
● OSCI maintains a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review.
● Incidents are classified by severity to ensure a response proportionate to impact, led by designated response roles and a cross-functional response team.
● External notifications to customers, regulators, and other parties are made only after review and approval by management and legal counsel, in accordance with applicable legal and contractual obligations.
● The incident response plan is reviewed at least annually and tested regularly, including through tabletop exercises.
7. Business Continuity and Disaster Recovery
● OSCI maintains a documented Business Continuity and Disaster Recovery (BC/DR) plan defining recovery objectives for critical services.
● Core operational services have a Recovery Time Objective (RTO) of 8 hours and a Recovery Point Objective (RPO) of 24 hours, supported by AWS's regional infrastructure.
● Backup and disaster recovery procedures are tested at least annually.
● OSCI's operations are designed to be independent of any single office location, allowing employees to shift to remote work — such as working from home — without disruption to production systems, email, or communications, even when office access is unavailable.
8. Physical Security
● Access to office space is restricted to authorized personnel through a biometric access control system.
● Areas housing critical infrastructure, such as server rooms, are subject to stricter access controls and are equipped with fire suppression systems and environmental monitoring.
● Areas handling production data and sensitive information are physically restricted through access authorization management and visitor controls.
● Physical security of the cloud data centers that make up OSCI's operating environment is managed by AWS under the shared-responsibility model.
9. Third-Party (Vendor) Risk Management
● Vendors and service providers undergo a security and privacy risk assessment prior to contracting, with cloud service providers subject to particularly rigorous review.
● Existing vendor relationships are periodically reassessed, and where vendors access OSCI systems or data, access is granted according to the principles of least privilege, time-limited scope, and prior approval.
10. Human Resources Security and Acceptable Use Policy
● All employees and contractor personnel provide written acknowledgment of OSCI's Information Security and Acceptable Use Policy (AUP), which defines standards for the appropriate use of company systems and data.
● Remote access requires a company-managed device, up-to-date endpoint protection, and multi-factor authentication (MFA).
● Access to company assets and systems is promptly revoked and blocked upon termination of employment.
● OSCI maintains a confidential reporting channel for raising suspected security or policy violations, and prohibits retaliation against anyone who makes a report.
11. Related Documents and Information
● Privacy Policy (includes Subprocessor List)
● Security Certifications and Reports: Available upon completion of SOC 2 certification
Contact Us
For questions about this whitepaper or OSCI's security practices, please contact your OSCI account representative or reach out to our security team at security@osci.kr.
This whitepaper provides a general summary of OSCI's security program for prospective and current customers and does not disclose the full details of OSCI's internal security policies. Internal policies are reviewed at least annually and are continuously updated to reflect OSCI's actual practices. Last updated: August 2026.