Otterly.AI names its AWS host's certifications on its own security page; insurance and audit-trail terms are unpublished
The AI-search visibility tool lists SOC 1, SOC 2 and ISO 27001 immediately after describing its hosting arrangement with Amazon Web Services. The certifications belong to AWS's data centers, not to an audit of Otterly.AI's own controls, and the company's site names no audit trail, insurance or indemnity terms.
Otterly.AI, a tool that tracks brand and product mentions across AI search engines, publishes a security page listing three certifications immediately after describing where its software runs. "The OtterlyAI software and all its services are hosted and managed within the AWS (Amazon Web Services) secure data centers. These centers all come with certain certifications: - SOC 1 and SOC 2/SSAE16/ISAE 3402 - ISO 27001," the page states. The certifications are Amazon Web Services'' own, covering the data centers Otterly.AI''s software runs in; the page does not state that Otterly.AI itself holds an independent audit of its own controls.
The product covers six AI answer surfaces, per its homepage: "Multi-AI Search Engine Coverage ChatGPT. Gemini. Perplexity. Copilot. AI Overviews. AI Mode. We track them all - and we''re just getting started." Pricing starts at $29 a month after a free trial: "We offer a free trial, and pricing starts at $29/month."
On regulatory alignment, the security page states GDPR compliance and nothing broader: "We are compliant with the EU General Data Protection Regulation (GDPR) which should help to protect personal data and give individual users more rights and control of their personal data. We are a processor in terms of GDPR. We are only storing some personal data (Personally Identifiable Information (PII)) in the form of name and email of your users. If we have a sub-processor that is not processing in the EU, we ensure through an EU-SCC and a DPA that the sub-processor has an adequate security standard." No EU AI Act or NIST AI Risk Management Framework alignment is stated.
Workspace access is split into two roles: "Enterprise authentication and SSO OtterlyAI can also provide to Enterprise customers Single-Sign-On via SAML (via our provider Clerk) Permissions and roles OtterlyAI offers different roles with different permissions within our system. Admins have all access and managing permissions, while members can only view most of the items." That governs which humans may use the workspace; it does not describe limits on what the software itself can do at run time.
On data handling, the company says customer data is not used for model training and describes its backup cycle: "All data is backed up daily, secured by encryption, and stored for 30 days. Deleted data is not removed from backups to allow for the possibility to recover in case of deletion. All previous backup data is removed after 90 days. We are reviewing our backups at least annually and simulate a full backup recovery. Logs Our system is storing logs to reproduce any faults or track security breaches. No personal data is stored within our logs. Usage of AI Whereever AI is used in the software processing, we are never actively using customer data for training the AI models."
The company''s site, reviewed by AI Dispatch, contains no reference to a customer-reviewable audit trail of the agent''s own actions, an insurance policy, an indemnity provision or a named carrier.
Sources 6
“The OtterlyAI software and all its services are hosted and managed within the AWS (Amazon Web Services) secure data centers. These centers all come with certain certifications: - SOC 1 and SOC 2/SSAE16/ISAE 3402 - ISO 27001”
otterly.ai · checked Sep 10, 2026“Multi-AI Search Engine Coverage ChatGPT. Gemini. Perplexity. Copilot. AI Overviews. AI Mode. We track them all - and we're just getting started.”
otterly.ai · checked Aug 8, 2026“We offer a free trial, and pricing starts at $29/month.”
otterly.ai · checked Aug 8, 2026“We are compliant with the EU General Data Protection Regulation (GDPR) which should help to protect personal data and give individual users more rights and control of their personal data. We are a processor in terms of GDPR. We are only storing some personal data (Personally Identifiable Information (PII)) in the form of name and email of your users. If we have a sub-processor that is not processing in the EU, we ensure through an EU-SCC and a DPA that the sub-processor has an adequate security standard.”
otterly.ai · checked Sep 10, 2026“Enterprise authentication and SSO OtterlyAI can also provide to Enterprise customers Single-Sign-On via SAML (via our provider Clerk) Permissions and roles OtterlyAI offers different roles with different permissions within our system. Admins have all access and managing permissions, while members can only view most of the items.”
otterly.ai · checked Sep 10, 2026“All data is backed up daily, secured by encryption, and stored for 30 days. Deleted data is not removed from backups to allow for the possibility to recover in case of deletion. All previous backup data is removed after 90 days. We are reviewing our backups at least annually and simulate a full backup recovery. Logs Our system is storing logs to reproduce any faults or track security breaches. No personal data is stored within our logs. Usage of AI Whereever AI is used in the software processing, we are never actively using customer data for training the AI models.”
otterly.ai · checked Sep 17, 2026