

Okaythis relies on a number of specialized technology providers to support the security, reliability, and delivery of its services. These providers are subject to internal third-party risk management processes in accordance with the Digital Operational Resilience Act (DORA) and other applicable regulatory requirements. The list below highlights key ICT service providers supporting our platform.
Name of Subcontractor | Category | Criticality | Service | Location | Certifications | Website |
Amazon Web Services (AWS) | Cloud Infrastructure | Hosting infrastructure used to operate and scale the Okaythis authentication platform. | EU regions and global infrastructure | ISO 27001, SOC 2, PCI DSS | ||
Linode | Cloud Infrastructure | Virtual server infrastructure used for development environments, testing infrastructure, and supporting platform services. | Global cloud infrastructure with multiple regional data centers | ISO 27001, SOC 2 | ||
Atlassian | Development Infrastructure | Collaboration and project management tools used for software development, issue tracking, and internal documentation. | Global cloud infrastructure | ISO 27001, SOC 2 | ||
ClickUp | Project Management | Task management and operational planning platform used to coordinate internal development and operational activities. | Global cloud infrastructure | SOC 2 | ||
Slack Technologies | Communication Services | Internal messaging and collaboration platform used for operational communication and incident coordination. | Global cloud infrastructure | SOC 2, ISO 27001 | ||
GitHub | Development Infrastructure | Source code repository hosting and version control platform used for software development and distribution of libraries through Swift Package Manager. | Global cloud infrastructure | SOC 2, ISO 27001 | ||
Google Workspace | Productivity and Collaboration | Email, document management, and collaboration tools supporting internal operations. | Global cloud infrastructure with regional data processing options | ISO 27001, SOC 2 | ||
Google Firebase | Mobile Platform Services | Critical ICT Provider | Backend services supporting mobile application functionality, including real-time services, analytics, and infrastructure required for delivery of Okaythis mobile authentication capabilities. | Global cloud infrastructure | ISO 27001, SOC 2 | |
Apple (Apple Push Notification Service) | Mobile Platform Infrastructure | Critical ICT Provider | Push notification infrastructure required for delivering authentication requests and transaction approvals to iOS devices through Apple Push Notification Service (APNs). | Global infrastructure operated by Apple | Apple platform security and privacy frameworks | |
CocoaPods | Development Infrastructure | Dependency management system used to integrate third-party libraries and components within iOS applications. | Global open-source ecosystem | Open-source project (community maintained) |

Okay is DORA compliant, ensuring our platform meets the EU’s Digital Operational Resilience Act requirements. We prioritize operational resilience, risk management, and security to help financial institutions remain compliant and protected.