Trust & Security.
Protecting organisations, opportunities, data and professional relationships across the OTHRS network.
Protected by design, at every layer.
From the moment an account is created to the documents shared inside a Deal Room, OTHRS applies defence-in-depth controls across identity, application and infrastructure.
Secure authentication
Email-verified accounts, hardened sign-in flows and short-lived sessions across every device.
Password protection
Industry-standard hashing, minimum complexity rules and rotation guidance enforced at registration.
Role-based access controls
Permissions scoped to organisation, plan tier and Deal Room participation — never global.
Account ownership controls
Verified company ownership, organisation transfer protections and admin recovery workflows.
Secure data storage
Tenant-isolated records held on UK and EU regions with continuous integrity checks.
Data encryption
TLS 1.2+ in transit and AES-256 equivalent encryption at rest across all primary stores.
Continuous monitoring
Anomaly detection, rate limiting and platform telemetry reviewed by the OTHRS engineering team.
Platform security practices
Least-privilege infrastructure, secrets vaulting, dependency scanning and reviewed releases.
Privacy is a product principle, not an afterthought.
Our approach to personal data aligns with the UK GDPR and PECR, with controls members can exercise directly from their account.
UK GDPR compliance
Lawful basis, transparent processing and clear data controller / processor responsibilities.
Data minimisation
We only collect what the platform genuinely needs to operate and connect organisations.
Your data rights
Access, rectification, erasure, restriction, portability and objection — supported under UK GDPR.
Subject access requests
Submit a SAR via your account and receive a structured response within one calendar month.
Data deletion requests
Close your account, delete your organisation profile and remove personal data on request.
Privacy by design
Privacy reviews built into every product change, not bolted on after launch.
Cookie controls
Granular consent for analytics, functional and marketing cookies — managed at any time.
A network you can actually rely on.
OTHRS is a verified network, not an open directory. Every layer of the product reinforces who you are dealing with and what they can do.
Verified organisations
Companies House, registered provider and care provider verification at the heart of the network.
Professional profiles
Named individuals tied to verified organisations — no anonymous accounts.
Organisation visibility
Controlled exposure: who sees your profile, capabilities and pipeline is yours to decide.
Reputation building
Profile strength, response activity and verified credentials build network credibility over time.
Structured opportunities
Standardised demand and opportunity formats reduce noise and surface genuine fit.
Secure collaboration
Move from match to Deal Room without leaving the platform — every step recorded.
A secure room for every conversation that matters.
Deal Rooms are the working surface for live opportunities. They're designed so commissioners, providers and developers can collaborate without leaking sensitive context.
Deal Rooms keep every collaboration accountable.
Every action inside a Deal Room is attributed to a verified individual at a verified organisation — and recorded against the opportunity it relates to.
Your account, defended.
The controls you don't usually see — quietly working in the background to keep your access safe.
Secure login procedures
Hardened sign-in flow with brute-force protections and IP-aware rate limiting.
Email verification
New accounts must verify the work email on the address before activating.
Password security
Hashed with modern algorithms, never logged and never sent over insecure channels.
Session protection
Time-bound sessions with the ability to sign out everywhere from your account.
Suspicious activity monitoring
Unusual sign-in patterns trigger alerts and, when needed, account safeguarding.
Multi-factor authentication
MFA support is on the roadmap and will be enforceable at the organisation level.
Governed by clear, public policies.
Every commitment we make is documented. Read the underlying policies for the full legal detail.
Data protection aligned with the UK General Data Protection Regulation.
Cookies and electronic communications handled per the Privacy and Electronic Communications Regulations.
The agreement between you and OTHRS for using the platform.
Professional conduct expected from every OTHRS member.
Plans, renewals, cancellations, refunds and VAT treatment.
Report a security concern.
If you've noticed something that doesn't look right, tell us. We treat every report seriously and respond promptly.
For confidential reports email legal@othrs.ai with the words "security report" in the subject. Avoid including sensitive proof in the first email — we will reply with a secure channel.
- Acknowledge every report within one UK working day.
- Investigate impact and confirm scope with you directly.
- Remediate, communicate and credit responsibly.
The OTHRS network, in numbers.
A live snapshot of network activity. Figures publish here as the platform scales.
Metrics update as the network grows. Audited figures will be published quarterly.