Built to survive procurement.
A security programme documented, testable, and portable across deployment topologies — from SaaS multi-tenant to bring-your-own-cloud.
What we do, at a glance.
TLS 1.3, AES-256 at rest, field-level encryption for PII/PAN.
BYOK / KMS integration on Enterprise. HSM-backed root keys.
US, EU, and Africa regions. Data does not leave your chosen region.
Signed, tamper-evident audit trail. Exportable to any SIEM.
Point-in-time recovery, cross-AZ replication, quarterly DR drills.
SSO, SCIM, IP allowlist, PrivateLink, MFA enforced for staff.
Where we are on the compliance ladder.
We publish our current status honestly. Where a certification is in progress, we tell you the timeline.
The control map we test against.
- OWASP ASVS-aligned SDLCEnforced
- Static analysis on every PREnforced
- Software composition scanningContinuous
- Secret scanningContinuous
- Web application firewallEnabled
- Private VPC per environmentEnforced
- Managed databases with encryptionEnforced
- Immutable, signed container imagesEnforced
- Vulnerability scanning of imagesContinuous
- Least-privilege IAMEnforced
- Background checks for staffEnforced
- Annual security awareness trainingEnforced
- Quarterly access reviewEnforced
- Vendor risk managementEnforced
- Documented incident response planTested
Everyone who touches your data.
Published and versioned. Notifications sent 30 days before any addition or change.
| Sub-processor | Purpose | Region |
|---|---|---|
| AWS | Cloud infrastructure | us-east-1 · eu-west-1 · af-south-1 |
| Cloudflare | DDoS, WAF, CDN | Global edge |
| Postmark | Transactional email | US |
| Plausible | Privacy-friendly analytics | EU |
| GitHub | Source control | US |
| Datadog | Observability & logs | US / EU |
We take security research seriously. If you believe you have found a vulnerability, please email us at security@oneaialert.com. We commit to acknowledging within one business day and to acting in good faith on any credible report.