OneAI
Security & trust

Built to survive procurement.

A security programme documented, testable, and portable across deployment topologies — from SaaS multi-tenant to bring-your-own-cloud.

Posture

What we do, at a glance.

Encryption in transit & at rest

TLS 1.3, AES-256 at rest, field-level encryption for PII/PAN.

Customer-managed keys

BYOK / KMS integration on Enterprise. HSM-backed root keys.

Data residency

US, EU, and Africa regions. Data does not leave your chosen region.

Audit logging

Signed, tamper-evident audit trail. Exportable to any SIEM.

Backups & DR

Point-in-time recovery, cross-AZ replication, quarterly DR drills.

Zero-trust access

SSO, SCIM, IP allowlist, PrivateLink, MFA enforced for staff.

Certifications

Where we are on the compliance ladder.

We publish our current status honestly. Where a certification is in progress, we tell you the timeline.

SOC 2 Type II
Type I complete. Type II report expected next audit window.
In progress
ISO/IEC 27001
Gap assessment complete. Certification targeted within 12 months.
Planned
PCI DSS
Merchant data touched under PCI DSS-aligned controls; formal attestation on Enterprise deployments.
Aligned
GDPR / UK-GDPR
DPA available; SCCs for international transfers.
Compliant
NDPR / CBN DPR
Nigerian Data Protection Regulation and CBN Data Protection Regulation.
Compliant
Controls

The control map we test against.

Application
  • OWASP ASVS-aligned SDLC
    Enforced
  • Static analysis on every PR
    Enforced
  • Software composition scanning
    Continuous
  • Secret scanning
    Continuous
  • Web application firewall
    Enabled
Infrastructure
  • Private VPC per environment
    Enforced
  • Managed databases with encryption
    Enforced
  • Immutable, signed container images
    Enforced
  • Vulnerability scanning of images
    Continuous
  • Least-privilege IAM
    Enforced
Organisational
  • Background checks for staff
    Enforced
  • Annual security awareness training
    Enforced
  • Quarterly access review
    Enforced
  • Vendor risk management
    Enforced
  • Documented incident response plan
    Tested
Sub-processors

Everyone who touches your data.

Published and versioned. Notifications sent 30 days before any addition or change.

AWS
Cloud infrastructure
us-east-1 · eu-west-1 · af-south-1
Cloudflare
DDoS, WAF, CDN
Global edge
Postmark
Transactional email
US
Plausible
Privacy-friendly analytics
EU
GitHub
Source control
US
Datadog
Observability & logs
US / EU
Responsible disclosure

We take security research seriously. If you believe you have found a vulnerability, please email us at security@oneaialert.com. We commit to acknowledging within one business day and to acting in good faith on any credible report.

Doing due diligence?

Request our SOC 2 report, security whitepaper, or DPA.