Skip to content
Optiml for advisors
Sign inStart free trial

Your clients' data, handled with care

Plan data is stored in Canada and encrypted. Clients can only view what you share, and only your practice can change a plan. Optiml's servers and database run on Amazon Web Services, in Canada.

Built on AWS, in Canada

Optiml's API and database run on Amazon Web Services in the Canada (Central) region, so you can tell a client exactly where their plan is stored.

Hosted in Canada
Optiml's application servers and database sit in AWS's Canada (Central) region. Every client's plan is stored there.
Audited infrastructure
AWS data centres are independently audited against SOC 1, SOC 2, SOC 3, ISO 27001 and PCI DSS, with physical security, power and network redundancy run by AWS.
A private network for the application
Optiml's API runs on AWS Lambda inside an Amazon Virtual Private Cloud (VPC).
Every infrastructure change recorded
AWS CloudTrail records every change made to Optiml's cloud infrastructure, in every AWS region.

Encrypted at rest and in transit

AES-256 on disk, modern TLS on the wire, and encryption keys managed by AWS.

AES-256 at rest
The database, its storage and its automated backups are encrypted with AES-256 using AWS Key Management Service (KMS). AWS rotates the encryption key automatically.
Encrypted file storage
Files Optiml stores in Amazon S3 are encrypted with AES-256, and every bucket that holds client data blocks all public access.
TLS 1.2 and 1.3 in transit
The Optiml app accepts only TLS 1.2 and TLS 1.3 connections, with forward secrecy. Older protocols are refused, and plain HTTP is redirected to HTTPS.
256-bit invite links
Every client invite carries a 256-bit random token. Optiml stores only its SHA-256 fingerprint, never the link itself, and the link works once and expires after five days.

Sign-in built for professionals

Your login opens every client file in your practice, so it gets the strongest protection we can put on it.

Auth0 by Okta
Sign-in runs on Auth0 by Okta, an identity platform independently certified to SOC 2 Type II and ISO 27001.
Two-factor authentication
Turn on two-factor authentication with an authenticator app such as Google Authenticator, Microsoft Authenticator or Authy: a time-based one-time code (TOTP) on top of your password.
Automatic sign-out
Each advisor chooses to be signed out after 15, 30 or 60 minutes of inactivity.
Every request verified
Every request to Optiml's API is checked against your signed sign-in token (JWT) before it runs, with no cached approvals.

Your practice decides who sees what

Access follows your firm's structure, and the rules are enforced on Optiml's servers, not just hidden on the screen.

Four roles
Owner, Organization Admin, Office Admin and Advisor. Organization Admins see the whole firm, Office Admins see their office, and Advisors see only the clients assigned to them.
Changes need an assignment
Changing a client's plan requires being assigned to that client, whatever your role.
Billing stays with the owner
Only the owner can change the subscription, update payment details, see invoices or cancel.
Clients view, they do not edit
A shared plan is view only for the client, enforced on Optiml's servers. Only your practice can change it.
Optiml support needs your permission
Our team can see your account only after you approve a support request. Access lasts one hour, and you can end it at any time.

Records, payments and EVA

The details your compliance team will ask about.

A history for every client
Optiml records each client's key events: invites sent and accepted, plans shared and opened, and advisors added, removed or reassigned.
Card details never touch Optiml
Payments run on Stripe's hosted checkout. Card numbers go straight to Stripe, a PCI DSS Level 1 service provider, and Stripe's notifications to Optiml are verified by signature.
Sensitive data kept out of logs
Passwords, sign-in tokens and card details are masked before anything is written to Optiml's logs.
Protected against injection
Database queries are parameterized, which blocks SQL injection.
EVA, the AI assistant
Last names are removed before plan data reaches EVA, and because EVA uses Google's paid AI API, plan data is not used to train Google's models.

Privacy you can explain to clients

Plain commitments, written into your agreement.

PIPEDA compliant
Optiml follows Canada's federal privacy law and never sells data.
Your practice stays in control
Your practice is the party to the agreement, and Optiml acts as a service provider for your client data. Read the advisor terms and advisor privacy policy.
Clear retention
If you cancel, your data is kept for 90 days so you can come back. A client you remove keeps the plans you shared for 90 days, then their data is deleted.
Breach notification
If a breach ever puts client data at real risk, Optiml notifies your practice without undue delay and gives you what you need to meet your own obligations.

Security questions

See it with your own clients.

Start a 14-day free trial, or book a demo and we will walk you through a full client plan.

Start your 14-day free trialBook a demo