OnComply

We use cookies to improve your experience and analyze site usage. Privacy Policy

Security

Security controls for sensitive vendor data

OnComply handles sensitive vendor information: banking details, tax identifiers, insurance information, and signed contracts. The controls below reflect that responsibility.

In transit & at rest
Encryption
Additional encryption
Sensitive fields
Database-enforced
Tenant isolation
7-year default
Audit log retention
Data Encryption

Your data is encrypted in transit and at rest

Vendor data is encrypted on the way in and where it is stored, and the most sensitive fields receive an additional layer of protection.

Encryption in transit and at rest

Traffic is served over HTTPS, connections to backend data stores are encrypted, and stored data, including every uploaded document, is encrypted at rest.

Extra protection for sensitive fields

Bank account details and tax identifiers receive an additional layer of application-level AES-256 encryption before they are stored, on top of storage-level encryption.

Managed encryption keys

Encryption keys are tenant-scoped and managed through a dedicated cloud key management service, with key usage logged.

Access Control

Your data is isolated and access is scoped

Tenant data isolation is enforced in the database layer in addition to application-level authorization, and role-based controls limit what each user can see and do.

Tenant data isolation

Each organization's data is isolated using database-enforced controls, so isolation between customers does not depend on application code alone.

Granular role-based access

Five distinct admin roles let you control exactly who can do what: Owner, Admin, Ops, Finance, and Auditor. Access to full payment details is limited to designated privileged roles.

Step-up authentication for sensitive actions

High-risk operations, like viewing full bank account details or downloading sensitive exports, require re-entering your password even if you're already signed in, and that elevated access expires after a short window.

Scoped API keys

API keys are created with specific, limited permissions and are securely hashed before storage.

Controlled support access

Support sessions are tied to a ticket your team opens, are strictly time-limited, and are recorded in your audit log with the operator's identity and the reason for access.

Authentication

Multiple layers of identity verification

Admin users, vendor portal users, and API integrations each authenticate in a way designed for how they're actually used.

Managed identity provider

Admin authentication is handled by a dedicated managed identity service, and requests are cryptographically verified.

Multi-factor authentication

MFA is required for privileged admin roles and can be enforced for any admin user. Verification codes are time-limited and attempt-limited.

Session security

Sessions are short-lived, and changing your password revokes active sessions across your devices.

Vendor portal security

Vendors use expiring, vendor-scoped portal links rather than shared credentials, and portal access is checked on the server for every request.

Brute-force protection

Authentication endpoints are rate-limited, and repeated failed attempts are flagged for review.

Application Security

Defense in depth across the platform

Modern browser protections, safe database access patterns, and layered validation applied consistently across the platform.

Modern browser protections

Application pages are served with a strict Content Security Policy and a full suite of security headers, including HTTPS enforcement, clickjacking protection, and restricted browser permissions.

Safe data access and validation

The application uses parameterized database access and input validation, and outbound webhook destinations are validated before delivery.

Secrets management

Production credentials are managed through dedicated secrets-management controls rather than living in application code.

Infrastructure

Cloud-native and monitored

OnComply runs on enterprise-grade cloud infrastructure with separation between public traffic, application workloads, and data storage.

Protected data stores

Databases and caches are not directly reachable from the internet; access flows through the application layer.

Backups and recovery

The database runs on a managed service with high availability, automated backups, and point-in-time recovery.

Security monitoring

Errors, performance, and anomalous behavior are monitored continuously to support reliability and incident response.

Audit & Compliance

A detailed record of what matters

Significant actions in OnComply are recorded in a protected audit log designed to support compliance reviews and investigations.

Protected audit log

Audit records are protected against modification after they are written, giving you a reliable record for compliance reviews and investigations.

Long-term retention

Audit logs are retained for seven years by default.

Broad event coverage

Key actions are recorded with who performed them, what was affected, and relevant context: vendor status changes, document validation decisions, contract signings, payment submissions, exports, failed sign-in attempts, and administrative changes.

Vendor compliance timeline and exports

Each vendor gets a single chronological timeline of status changes, document events, contract activity, and communications, and you can export audit history for your organization or any single vendor at any time. Audit exports are themselves recorded.

AI processing transparency

AI document processing is disclosed up front

Microsoft Azure processes documents for automated extraction and validation. Our Data Processing Agreement explains what Azure receives and Microsoft's training and retention commitments.

Running a security review?

We're happy to support procurement and security assessments. Request additional security documentation, ask follow-up questions, or set up a review call with the team.

Request security documentation

Responsible Disclosure

If you discover a security vulnerability in OnComply, please report it to us at support@oncomply.biz. We will acknowledge your report within 24 hours and work with you to understand and address the issue. We do not pursue legal action against researchers acting in good faith.

Please include a description of the vulnerability, steps to reproduce, potential impact, and any suggested remediation. We will keep you informed throughout the investigation.

W-9 CollectionCOI TrackingACH AuthorizationDocument Fill & SignAutomated ValidationRenewal RemindersCan-Work / Can-Pay ControlsVendor PortalCompliance DashboardWebhook IntegrationsEligibility APIAudit-Ready ExportsLicense TrackingGrace Period ManagementCustom FormsW-9 CollectionCOI TrackingACH AuthorizationDocument Fill & SignAutomated ValidationRenewal RemindersCan-Work / Can-Pay ControlsVendor PortalCompliance DashboardWebhook IntegrationsEligibility APIAudit-Ready ExportsLicense TrackingGrace Period ManagementCustom Forms