Security Statement OCAI.pro
Last updated: 12 August 2026
K&S KnowledgeLab BV, trading under the name OCAI.pro, considers information security an integral part of its AI commerce platform, online store and business operations.
This Security Statement describes our principles for protecting systems, personal data, orders, payments, product information, AI functionality and technical integrations. Measures are implemented on a risk-based basis and further developed as OCAI.pro grows.
No digital system is completely free of risk. This statement therefore does not constitute a guarantee that a malfunction, vulnerability or security incident will never occur.
OCAI.pro does not claim ISO 27001, SOC 2, PCI DSS, NEN or other certification unless it has actually been obtained and can be demonstrated independently.
1. Organization and scope
K&S KnowledgeLab BV
Trading under the name OCAI.pro
Bolderweg 2, building E, office 15
1332 AT Almere
Netherlands
KvK number: 60271477
VAT number: NL853837302B01
E-mail: info@ocai.pro
Privacy: privacy@ocai.pro
This statement applies to:
- the OCAI.pro website and online store;
- AI search, analysis and recommendation functions;
- accounts, shopping carts and checkout processes;
- order, payment, return and service processes;
- application code, APIs and technical integrations;
- databases and production infrastructure;
- administration environments and internal commerce functions;
- connections with suppliers and service providers.
External parties manage parts of the technical and operational chain. Their own security policies, responsibilities and contractual arrangements apply to their systems.
2. Security principles
OCAI.pro applies the following principles:
- Confidentiality: information is accessible only to authorized persons and systems.
- Integrity: data and software are protected against unauthorized or unintended modification.
- Availability: critical functions should be appropriately available and recoverable.
- Authenticity: identities, transactions and system interactions should be verifiable where necessary.
- Traceability: relevant events should be investigable.
- Least privilege: users and systems receive only the access necessary to perform their tasks.
- Layered security: prevention, detection, response and recovery complement each other.
3. Security governance
K&S KnowledgeLab BV is responsible for the governance of information security within OCAI.pro. Security is integrated with business operations, privacy, software development, supplier management and continuity.
Governance focuses on:
- clear ownership of systems and information;
- risk-based decision making;
- controllable changes and releases;
- limitation and periodic review of access;
- timely handling of incidents and vulnerabilities;
- assessment of critical suppliers;
- compliance with applicable laws and regulations;
- continuous improvement of measures.
Roles and responsibilities are assigned proportionally to the size of the organization. Critical decisions and exceptions must be traceable.
4. Risk management
Risks are assessed based on likelihood and potential consequences for customers, data, transactions, operations and service delivery.
In the assessment we consider, among other things:
- sensitivity and volume of data;
- criticality of systems and integrations;
- dependency on external parties;
- potential financial or operational abuse;
- impact on confidentiality, integrity and availability;
- technical vulnerabilities and current threats;
- recoverability and available mitigations.
Risks may be avoided, mitigated, transferred or accepted with justification. Risks with high practical impact are prioritized.
5. Infrastructure and network security
OCAI.pro uses a modern web application architecture with application, API and data components. Production services run on server and cloud platforms.
Configuration is, where applicable, focused on:
- HTTPS for public web connections;
- limiting publicly reachable services;
- secure database and API connections;
- separation of code, configuration and secrets;
- separate configurations per environment;
- management of domains, DNS and certificates;
- timely installation of relevant security updates;
- control of critical infrastructure changes.
Only necessary network services should be externally reachable. Management interfaces are restricted where the infrastructure supports this.
Firewall rules, server configuration and allowed ports should match the services actually in use. Unused services and access should be disabled.
6. Identity and access management
Access to systems and data is based on identity, role, technical necessity and the principle of least privilege.
Principles include:
- personal accounts where practically feasible;
- strong and unique passwords;
- multi-factor authentication where available and appropriate;
- role- and permission-based access;
- restricted access to production and databases;
- no unnecessarily shared administrator accounts;
- revocation of access when no longer required;
- periodic review of critical access rights;
- secure recovery and login procedures.
API tokens and technical accounts receive only the rights necessary for their task. Unused keys and accounts should be revoked.
7. Data protection
OCAI.pro limits data processing to what is necessary for the website, AI functionality, orders, payments, delivery, customer service, security and legal obligations.
Protection focuses on:
- purpose limitation and data minimization;
- access restriction based on necessity;
- protection during data transfer;
- limited storage of payment data;
- limiting production data in test environments;
- retention periods and controlled deletion;
- protection of backups;
- controlled disclosure to suppliers.
Users should not place passwords, full payment details, security codes, special category personal data or trade secrets in free-form search or AI input fields.
More information is available in the Privacy Statement.
8. Encryption and secret management
Public connections to OCAI.pro are secured via HTTPS when the production environment is correctly configured. This protects data during transport between browser and server.
Secret management is focused on:
- storing keys and tokens outside public source code;
- separate values per relevant environment;
- limiting access to secrets;
- no inclusion of secrets in logs;
- rotation in case of potential exposure;
- revocation of no longer used keys;
- minimal privileges for technical integrations.
Encryption reduces risk but does not replace careful access, configuration and key management.
9. Secure development lifecycle
Security is considered during design, development, change, testing and deployment of functionality.
The development approach includes, where appropriate:
- version control of application code;
- separate branches for changes;
- assessment of change impact;
- type, lint and build checks;
- functional tests of critical routes;
- validation of input and output;
- server-side authorization for protected actions;
- limitation of sensitive error information;
- review of software dependencies;
- recovery options via version control.
A successful build demonstrates that software can be technically assembled, but does not constitute a full penetration or security test.
10. Change and release management
Changes to production functionality must be traceable, controllable and recoverable.
A controlled change includes, where appropriate:
- definition of purpose and scope;
- verification of the existing state;
- limited and traceable code changes;
- lint, type and build validation;
- functional verification of relevant routes;
- commit and available rollback point;
- verification of the production rollout.
Emergency changes may require a shortened process but must be reviewed and documented afterwards.
11. Vulnerability management
OCAI.pro strives to identify and treat vulnerabilities in code, dependencies, configurations and infrastructure in a timely and risk-based manner.
The approach consists of:
- inventory of software and components;
- checking relevant security updates;
- assessment of known vulnerabilities;
- prioritization based on exploitability and impact;
- patching, mitigating, replacing or disabling;
- validation after remediation;
- documentation of relevant risk acceptances.
OCAI.pro does not publish fixed remediation times as a contractual guarantee, unless separately agreed in writing.
12. Logging and monitoring
Relevant technical and operational events may be recorded to investigate availability, errors, abuse, transactions and incidents.
Logging may include:
- application and server errors;
- login and authorization events;
- API and integration errors;
- order, payment and status transitions;
- publication and administration actions;
- unusual or failed requests;
- availability and technical performance;
- incident investigation and recovery.
Logs are not intended to contain passwords, full payment details or unnecessary confidential information. Access and retention periods are limited.
Monitoring supports detection but does not guarantee that every attack, error or anomaly will be discovered immediately.
13. Security incident management
A security incident is an event that may affect the confidentiality, integrity or availability of systems, services or information.
Incident response is focused on:
- registration and initial assessment;
- classification of severity and potential impact;
- limiting further damage;
- securing relevant technical information;
- investigation of root cause and affected components;
- restoration of secure service delivery;
- communication where necessary;
- evaluation and structural improvement.
During an incident, functions may be temporarily limited where this is necessary to protect customers, data or infrastructure.
14. Data breaches
When an incident involves personal data, OCAI.pro assesses whether it constitutes a data breach under the GDPR.
The assessment includes, among other things:
- the nature and scope of the data;
- the number and categories of affected individuals;
- possible consequences for rights and freedoms;
- likelihood of misuse;
- security and remediation measures taken;
- necessity of notification and communication.
Where legally required, a data breach is reported to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Affected individuals are informed when the breach is likely to result in a high risk and no legal exception applies.
Incidents and data breach assessments are documented in accordance with the GDPR.
15. Supplier and supply chain security
OCAI.pro uses suppliers for hosting, databases, payments, product data, fulfilment, shipping, communication and possibly AI services, among others.
Relevant suppliers are assessed on a risk-based basis for:
- nature and sensitivity of processed data;
- criticality of the service;
- access rights and technical connections;
- available security information;
- privacy and processor agreements;
- incident and notification obligations;
- location of data processing;
- continuity and replaceability;
- termination and removal of access.
A supplier's certification can provide useful assurance but does not replace assessment of the specific service, configuration and shared responsibilities.
16. Payment security
Payments are processed through specialized payment service providers. Full card details and security codes should be processed directly by the payment service provider.
For orders, OCAI.pro primarily processes payment status, amount, payment method and a transaction identification.
Security is, where applicable, focused on:
- encrypted transfer to the payment service provider;
- server-side verification of payment statuses;
- validation of callbacks and webhooks;
- prevention of manipulation of amounts;
- separation between order and payment confirmation;
- recording of relevant status transitions;
- investigation of suspicious or duplicate transactions.
a browser return page alone is not definitive proof of payment. The payment status is verified server-side where configured.
17. AI security
AI security is addressed as part of application, data, access and supplier security.
17.1 Untrusted input
User input, supplier content and external product data are treated as potentially untrusted. They must not automatically receive unlimited system privileges.
17.2 Prompt injection and manipulation
External texts may contain hidden instructions or manipulative content. The security approach aims to distinguish system policies, user queries and external product information from each other.
17.3 Limited privileges
AI functionality should only have access to functions and data necessary for the task. Critical actions are protected by additional authorization and policy controls.
17.4 Product, price and payment integrity
AI output must not independently determine a final price, payment status, stock status or contractual product information when an authoritative application or supplier source is available.
17.5 Publication and profit policy
OCAI.pro uses policy controls to review products and prices before they are eligible for publication or sale. AI output does not replace these controls.
17.6 Transparency and human oversight
Results may indicate reasons, warnings, confidence indicators and missing data. Where uncertainty is insufficient or consequences are material, additional review may be required.
17.7 Limitations
AI can produce incorrect, incomplete or outdated results. Essential product information, price, availability, suitability and delivery must be verified prior to ordering.
18. Continuity, backup and recovery
Continuity measures focus on the recovery of critical application, configuration and data functions after an outage or incident.
The approach includes, where configured:
- version control of application code;
- release recovery points;
- backup of relevant systems and data;
- protection of backup data;
- documentation of critical dependencies;
- restart and recovery procedures;
- review of DNS and certificate dependencies;
- assessment of database recovery capabilities.
The presence of a backup does not guarantee that recovery will always be complete or within a specific timeframe. Backup and recovery configurations should therefore be tested.
Specific recovery objectives or availability guarantees apply only when agreed in writing.
19. Privacy by design
Privacy and security are handled together. New and changed processes are assessed where relevant for:
- necessity and proportionality;
- legal basis and transparency;
- access rights and suppliers;
- retention periods and deletion;
- international transfers;
- risks to data subjects;
- appropriate security measures.
When a processing operation is likely to result in a high privacy risk, it is assessed whether a data protection impact assessment is necessary.
20. User responsibilities
Users can reduce risks by:
- using a strong and unique password;
- never sharing login credentials;
- keeping devices and browsers up to date;
- logging in only via the official domain;
- not opening suspicious messages and links;
- not placing sensitive data in search fields;
- verifying order and payment details;
- reporting suspected abuse immediately;
- logging out on shared devices.
OCAI.pro will not request a full password or a full card security code by e-mail.
21. Responsible disclosure
Do you believe you have found a security vulnerability? Report it via info@ocai.pro with the subject Securitymelding OCAI.pro.
Please include, if possible:
- the affected URL, function or component;
- a clear description;
- safe reproduction steps;
- the potential impact;
- relevant technical information;
- contact details for feedback.
We request researchers to:
- not disclose publicly before coordination;
- not view personal data of others;
- not modify or delete data;
- not perform phishing or social engineering;
- not perform denial-of-service;
- not create persistent access;
- stop once sensitive access is demonstrated.
This statement is not a bug bounty program and does not contain any commitment to financial reward. It also does not authorize unlawful or harmful actions.
22. Contact and changes
K&S KnowledgeLab BV / OCAI.pro
For the attention of Security
Bolderweg 2, building E, office 15
1332 AT Almere
Netherlands
E-mail: info@ocai.pro
Do not include passwords, full payment details or unnecessary personal data in a report.
This Security Statement may be updated when infrastructure, suppliers, processes, threats, legislation or security measures change.
Also read the Privacy Statement, the Terms and Conditions and the returns information.