Corporate Governance, Policies & Compliance Reports
Public repository of Ozikol's corporate governance policies, ISO 27001 certifications, SOC 2 Type II audit summaries, accessibility standards, and ethical vendor charters.
1. Executive Corporate Governance Framework & Board Oversight
Ozikol is committed to the highest standards of corporate governance, business integrity, technical reliability, and social responsibility. Our executive leadership team and Board of Directors maintain active oversight over information security, regulatory compliance, risk management, and ethical corporate conduct. Our governance model ensures that commercial objectives are achieved in full harmony with statutory legal obligations and customer data sovereignty.
2. Master Enterprise Compliance Register
The following register outlines the core operational policies governing all Ozikol corporate operations, engineering departments, and infrastructure partnerships:
2.1 Information Security Management System (ISO/IEC 27001:2022)
Our information security program is structured strictly in accordance with ISO/IEC 27001:2022 and NIST Cybersecurity Framework (CSF) standards. Our controls encompass continuous vulnerability assessments, weekly automated static code analysis (SAST), third-party penetration testing, hardware-backed administrative access controls, and comprehensive employee cybersecurity certification.
2.2 SOC 2 Type II Compliance Framework
Ozikol undergoes annual independent SOC 2 Type II examinations conducted by accredited third-party auditing firms. The examination verifies our operational controls across the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria for Security, Availability, and Confidentiality.
2.3 Business Continuity & Disaster Recovery (BCDR) Policy
Our platform is engineered for continuous resilience against regional infrastructure disruptions. All client databases feature point-in-time recovery with geo-redundant backups replicated across paired sovereign cloud availability zones:
- Recovery Point Objective (RPO): Less than fifteen (15) minutes for all transactional databases.
- Recovery Time Objective (RTO): Less than two (2) hours for complete automated regional failover.
- Tabletop Drills: Emergency failover procedures and incident response plans undergo live simulation testing bi-annually.
2.4 Accessibility & Universal Inclusion (WCAG 2.1 Level AA)
We believe enterprise software must be accessible to all users regardless of physical ability. Our engineering teams rigorously audit our central web portals, executive MIS systems, and mobile applications to maintain conformance with the Web Content Accessibility Guidelines (WCAG 2.1 Level AA). This includes full keyboard navigation, ARIA screen-reader support, high-contrast color palettes, and resizable typography.
2.5 Modern Slavery & Human Rights Statement
Ozikol enforces an absolute zero-tolerance policy regarding forced labor, servitude, human trafficking, and child labor across our global operations, sub-contractors, and technology supply chains. We comply with the UK Modern Slavery Act 2015 and require all hardware suppliers (including manufacturers of POS thermal printers, turnstiles, and biometric devices) to certify compliance with fair labor and human rights standards.
2.6 Anti-Bribery, Anti-Corruption & Whistleblower Protection
Ozikol operates in strict compliance with the UK Bribery Act 2010, the US Foreign Corrupt Practices Act (FCPA), and applicable international anti-bribery statutes. We prohibit the offering, solicitation, or acceptance of any bribe, kickback, or improper commercial inducement. Our independent whistleblower channel provides secure, anonymous reporting with complete non-retaliation protections for employees and partners.
2.7 Coordinated Vulnerability Disclosure (CVD) & Bug Bounty
We actively collaborate with ethical cybersecurity researchers to enhance platform resilience. Our Coordinated Vulnerability Disclosure policy provides clear safe-harbor terms for security research conducted in good faith. Vulnerabilities may be reported directly to our security engineering team, and we commit to initial triage within twenty-four (24) hours.
3. Hardware Peripheral, Thermal Printer & Edge Driver Standards
Ozikol provides native desktop and edge applications interfacing directly with physical hardware peripherals (including ESC/POS thermal receipt printers, barcode/QR scanners, turnstiles, and biometric readers). Our hardware driver architecture guarantees:
- Direct Driver Execution: Peripheral communication executes strictly in volatile memory; print spool data and barcode read streams are never cached to unencrypted permanent storage.
- Hardware Compatibility Certifications: Official support for standard USB, Ethernet, and serial peripheral protocols meeting international electrical and electromagnetic compatibility standards (CE, FCC, RoHS).
4. Environmental Sustainability & Green Cloud Operations
Ozikol recognizes our ecological responsibility. We deploy exclusively on tier-1 sovereign cloud infrastructure (Microsoft Azure and Amazon Web Services) committed to achieving 100% carbon-neutral operations powered by renewable energy. Furthermore, our digital access passes, digital dues receipts, and paperless elections have eliminated millions of sheets of paper across hundreds of subscribing estates and institutions.
5. Transparency Reporting & Law Enforcement Inquiries
Ozikol maintains strict protocols regarding government, law enforcement, and regulatory requests for customer data:
- No Backdoors: Ozikol does not build encryption backdoors or master decryption keys into any of its client workspaces, databases, or native binaries.
- Statutory Subpoena Verification: Customer data will never be disclosed to law enforcement without a legally binding court order, search warrant, or subpoena issued by a court of competent jurisdiction.
- Mandatory Customer Notice: Unless explicitly prohibited by a lawful non-disclosure gag order issued by a judge, Ozikol will promptly notify the affected customer organization before disclosing any records, providing the opportunity to seek protective legal remedies.
6. Accessing Audit Reports and Compliance Dossiers
Enterprise prospective clients and current institutional subscribers may request confidential access to our comprehensive compliance dossiers, including our SOC 2 Type II examination reports, ISO 27001 summary certificates, and standard Data Processing Addendums (DPAs). To request these documents under mutual non-disclosure, please visit our Certifications & Compliance Hub or contact our enterprise team via our Enterprise Support Portal.
Published Governance & Compliance Directory
Explore our active legal agreements and transparency charters:
Ozikol Master Privacy Notice & Data Sovereignty Charter
Comprehensive legal transparency detailing how Ozikol isolates, processes, safeguards, and respects institutional data across our 9 operational suites, web portals, executive MIS, mobile apps, and edge desktop clients.
Terms of Use & Master Subscription Agreement
The definitive contractual framework governing enterprise subscriptions, dedicated cloud instance provisioning, client software licensing, service level commitments, and acceptable use across the Ozikol ecosystem.
Cookie & Tracking Technologies Policy
A clear, comprehensive breakdown of operational cookies, authentication tickets, local storage tokens, and our uncompromising zero-third-party-ad-tracker pledge.
Your Privacy Choices & Data Subject Rights Portal
Self-service guidance and official procedures for exercising your statutory privacy rights under GDPR, UK GDPR, CCPA/CPRA, and NDPA across the Ozikol ecosystem.
Corporate Governance, Policies & Compliance Reports
Public repository of Ozikol's corporate governance policies, ISO 27001 certifications, SOC 2 Type II audit summaries, accessibility standards, and ethical vendor charters.