Trust Center

Security, privacy, and compliance are foundational to the platform. This page is the authoritative source for Onam's certifications, security posture, policies, and compliance artifacts. Every claim below is independently audited or backed by a downloadable artifact.

Trust center overview — SOC 2 Type II, ISO 27001, data encryption, penetration testing, GDPR compliance, and uptime SLA
Trust center overview — SOC 2 Type II, ISO 27001, data encryption, penetration testing, GDPR compliance, and uptime SLA

Certifications and compliance status

The platform holds the major enterprise security certifications. Six are achieved, two are in progress, and three are on the roadmap. All achieved certifications are backed by current audit reports available on request.

CertificationStatusScopeAudit period
SOC 2 Type IIAchievedSecurity, Availability, ConfidentialityAnnual — report on request
ISO 27001:2022AchievedISMS for cloud platform operationsAnnual — certificate on request
ISO 27017AchievedCloud-specific security controlsCo-certified with ISO 27001
PCI DSS v4.0AchievedCard data handling in billing pipelineAnnual — attestation on request
GDPRCompliantEU personal data processingDPA available — contact legal@onam.io
CSA STAR Level 1AchievedCAIQ self-assessment publishedSee Downloads below
HIPAA BAAAvailableBusiness Associate AgreementContact sales@onam.io
ISO 27018In progressCloud privacy for PIITarget: Q3 2026
FedRAMP ModerateIn progressUS federal agency useTarget: Q4 2026
ISO 27701PlannedPrivacy managementTarget: 2027 H1
SOC 3PlannedPublic-facing assurance reportTarget: 2027 H1
IRAP (Australia)PlannedAustralian Government useTarget: 2027 H2

Downloads

DocumentAccessLast updated
SOC 2 Type II ReportOn request — NDA required2025-12
ISO 27001 CertificatePublic2025-09
ISO 27017 CertificatePublic2025-09
PCI DSS v4.0 AOCOn request — NDA required2025-11
Penetration Test Report (summary)On request2026-03
Penetration Test Report (full)On request — NDA required2026-03
CAIQ Self-AssessmentPublic2026-04
SIG LiteOn request2026-04
Data Flow DiagramPublic2026-05
Disaster Recovery Test ReportOn request2026-01
Subprocessor ListPublicUpdated on change
Data Processing Agreement (DPA)Public2026-01
To request gated documents, email trust@onam.io. NDA-gated documents (SOC 2 report, full pentest report, PCI AOC) are typically turned around within two business days.

Security program

The security program is organized into five domains. Each domain has named owners, written policies (reviewable under NDA), and quarterly audit cycles. The summary below is the public-facing version; the full policy set is part of the SOC 2 audit report.

DomainWhat it covers
InfrastructureSOC 2-certified cloud infrastructure · AES-256 encryption at rest · all traffic over TLS 1.3 · environment isolation per tier · no public database endpoints
ApplicationOWASP Top 10 controls · RBAC at every layer · input validation on every endpoint · dependency scanning in CI/CD · SAST on every pull request
IdentityMFA enforced for all staff · privileged access management · quarterly access reviews · SSO for all internal tooling
OperationalAnnual third-party penetration test · quarterly vulnerability scans · 24/7 security monitoring · SOC 2 annual audit · public bug bounty program
DataTenant isolation with no shared tables · AES-256 at rest · TLS 1.3 in transit · 30-day backup retention · regional data residency options

Penetration testing

Independent third-party security firms conduct annual penetration tests covering:

  • External network penetration testing
  • Web application security testing (OWASP Top 10)
  • API security testing
  • Privilege escalation and lateral movement
  • Multi-tenant isolation validation
  • Subprocessor boundary testing

A summary report is available on request; full reports are available under NDA for enterprise customers. Identified findings are remediated on the same SLA we promise customers — Critical within 7 days, High within 30, Medium within 90.

Data handling

The platform stores three classes of data: scan and finding data (your security posture), credential references (pointers to your IAM roles, never plaintext keys), and account metadata. Encryption, retention, and isolation rules are explicit per class.

Data typeWhere storedEncryptionRetention
Cloud resource configurationsTenant-scoped databaseAES-256 at rest12 months
Security findingsTenant-scoped databaseAES-256 at rest12 months
Scan metadataTenant-scoped databaseAES-256 at rest12 months
Audit logsTenant-scoped databaseAES-256 at rest7 years
Cloud credentials (references only)Managed secret storeCloud-provider KMSDuration of subscription
User account dataIdentity backendAES-256 at rest90 days post-termination
Attack graph dataManaged graph databaseAES-256 at rest12 months

We never store:

  • Plaintext cloud credentials. Only credential references (ARNs, service principal IDs) are stored. The secret material lives in a managed secret store (AWS Secrets Manager, encrypted with KMS) and is fetched at scan time.
  • Customer workload data or file contents. Data Security (DSPM) samples to classify data types — sample data is discarded immediately after classification metadata is extracted.
  • Personal data from scanned cloud resources. The platform records that PII, PCI, or PHI exists, where it lives, and how it is protected — never the data itself.

Subprocessors

SubprocessorPurposeLocation
Cloud infrastructure providerCompute, storage, secrets managementap-south-1 (primary), region-configurable
Managed graph database serviceSecurity graph (attack paths)Region-configurable
Payment processorSubscription billingGlobal
Transactional email providerSystem notificationsGlobal
Incident alerting serviceInternal on-call rotationGlobal

Customers are notified of material subprocessor changes 30 days in advance. The current list is published and updated whenever a change occurs; subscribe to change notifications at trust@onam.io.

Incident response

Security events are handled through a five-stage response process. Severity is classified within 1 hour of detection; customer notifications go out within 72 hours of confirming impact.

Incident response flow — Detect, Triage, Respond, Notify, Post-Incident Review
Incident response flow — Detect, Triage, Respond, Notify, Post-Incident Review
StageTarget SLAWhat happens
1. DetectContinuous (24/7)Security event detected via 24/7 monitoring, SIEM correlation, or customer report
2. TriageUnder 1 hourSeverity classified; response team paged
3. RespondCritical: immediate · High: 4 hours · Medium: 24 hoursIncident response team mobilizes; containment begins
4. NotifyWithin 72 hours of confirmed customer impactGDPR Article 33-compliant notification to affected customers
5. Post-incident reviewWithin 14 days of resolutionPIR shared with affected customers, including root cause and prevention measures

To report a security issue: security@onam.io. A GPG public key, a responsible disclosure policy, and a bug bounty program are all published on the website.

Business continuity

MetricTarget
RTO (Recovery Time Objective)4 hours for full platform recovery
RPO (Recovery Point Objective)1 hour (continuous database backups)
Backup frequencyContinuous backups; daily snapshots retained 30 days
DR test frequencySemi-annual — last test 2026-01 (report on request)
Multi-AZ deploymentAll production databases run multi-AZ within your selected region
Cross-region failoverAvailable on Enterprise plans with documented RTO/RPO

Security ratings

ServiceRatingLast updated
SecurityScorecardA (94 / 100)2026-05
BitSight790 (Advanced)2026-05
UpGuard900+2026-05

Live ratings auto-refresh on the trust center web page; score histories are available on request.

Contact

PurposeContact
Security issues and vulnerabilitiessecurity@onam.io
Trust document requests (SOC 2, pentest)trust@onam.io
Data protection, GDPR, DPAlegal@onam.io
HIPAA BAA or FedRAMP questionssales@onam.io
General compliance questionscompliance@onam.io

Trust Center updates are published when certifications are renewed or materially changed. Last updated: 2026-05-09.

Next steps

  • Data Retention — what we store, for how long, and how deletion works
  • SLA & SLO — uptime commitments, scan SLOs, and support response times
  • Framework Coverage — the 70+ compliance frameworks the platform evaluates for you
  • Book a demo — walk through the security architecture with our team