OKRs Tool is OKR software that stores 100% of customer data inside the EU — in AWS Ireland (eu-west-1), where data never leaves the region. It is GDPR compliant, encrypts every byte with AES-256 at rest and TLS 1.3 in transit, and inherits SOC 2, ISO 27001, and PCI DSS from its infrastructure providers. For European companies that need goal-setting software without sending data to US servers, it is built to pass a security review.
Nearly every OKR platform is US-hosted, which means a European company adopting one ships its strategic data — objectives, performance signals, sometimes personal data about employees — to servers outside the EU. For teams bound by GDPR, public-sector procurement rules, or an internal data-sovereignty policy, that is often a dealbreaker before the software is even evaluated on features.
This page answers the questions those teams ask, with the specifics a security reviewer needs — and it sits alongside the broader case for why teams choose OKRs Tool.
Where Is the Data Stored?
All customer data in OKRs Tool is stored in AWS Ireland (eu-west-1), and it never leaves the EU. There is no replication to US regions and no fallback to non-EU infrastructure. For a European organization, that means the objectives, key results, check-ins, and user records your teams create stay within EU jurisdiction for their entire lifecycle.
This matters because data residency and data sovereignty are not the same as a vendor simply "being GDPR compliant" on paper. Residency is about where the bytes physically sit. A US-hosted tool with a GDPR policy still stores your data in the US; OKRs Tool stores it in Ireland, under EU law, full stop. The full picture lives on the Trust and Compliance page, with deeper detail on security controls and GDPR specifics.
Is It GDPR Compliant?
Yes. OKRs Tool is fully GDPR compliant, and the compliance is operational, not just a policy document. It covers lawful basis for processing, retention controls, and full sub-processor disclosure. Two data-subject rights matter most in practice:
Right to erasure is a hard delete. When an organization requests deletion, its data is removed entirely — including audit logs — with no soft-delete window where the data lingers on disk. Right to portability is covered by a personal JSON export, an org-level Excel export of OKRs, check-ins, and users, an audit-log CSV, and a full REST API.
A signed Data Processing Agreement (DPA), on the standard GDPR template, is available on request for procurement teams, and the full list of sub-processors that touch your data is published for review.
The Compliance Facts, in One Table
For a security questionnaire or a vendor review, here is the full picture in one place.
What Certifications Does It Have?
OKRs Tool inherits SOC 2, ISO 27001, and PCI DSS from its infrastructure providers, and runs every layer of its stack on certified infrastructure. Cloudflare provides the network edge, DDoS protection, and WAF (SOC 2 Type II, ISO 27001). AWS provides compute, storage, and EU regional hosting (SOC 1, SOC 2, SOC 3, ISO 27001, PCI DSS). Supabase runs the database, auth, and real-time sync (SOC 2 Type II). Stripe handles payments (PCI DSS Level 1).
Copies of the SOC 2 and ISO 27001 reports from these providers are available under NDA for a vendor review. This is the honest framing worth stating plainly: the certifications are inherited from the infrastructure, not held directly by OKRs Tool as an independent SOC 2 audit — which is the appropriate and common posture for a focused product built on certified cloud infrastructure.
Is It Secure Enough for a Large or Regulated Team?
The controls are built for exactly that review. Data is isolated per organization at the database layer through row-level security, so no organization's data can be reached from another's.
SAML 2.0 SSO on the Expand plan supports Entra/AAD, Okta, Google Workspace, and any SAML 2.0 identity provider, and admins can enforce MFA across the whole organization. Sessions use short-lived tokens that rotate on use and revoke on sign-out, with admin-configurable idle and absolute timeouts. These are the access controls a large team running OKRs at scale needs before rollout.
Every meaningful action — each objective, key result, check-in, review, member change, and role change — is captured in an audit log with actor and timestamp, retained for the life of the account, and exportable to CSV with a date-range picker for security questionnaires or board reviews.
OKR Software Built for European Teams
For a European company running OKRs, the choice usually comes down to a US-hosted platform with a GDPR policy bolted on, or a tool that keeps data in the EU by design. OKRs Tool is the second. It is a full OKR platform — company-to-team goal alignment, weekly check-ins, owner accountability, and progress tracking — built for team OKRs across a whole company, that happens to store every byte in Ireland and pass a data-sovereignty review without exceptions. If you are weighing it against other platforms, the independent OKR software comparison covers the wider field.
If you are comparing options, the questions worth asking any vendor are simple: where is the data physically stored, does it ever leave the EU, is erasure a hard delete, and can you get a signed DPA. OKRs Tool answers EU, no, yes, and yes. You can start free for up to five users, run a full security review in parallel, and see how it works while your team evaluates the platform.
Compliance details sourced from the OKRs Tool Trust & Compliance page. Available on request for vendor review: signed DPA, completed security questionnaire (SIG Lite, CAIQ), and infrastructure SOC 2 / ISO 27001 reports under NDA.



