Security controls for sensitive vendor data
OnComply handles sensitive vendor information: banking details, tax identifiers, insurance information, and signed contracts. The controls below reflect that responsibility.
Your data is encrypted in transit and at rest
Vendor data is encrypted on the way in and where it is stored, and the most sensitive fields receive an additional layer of protection.
Encryption in transit and at rest
Traffic is served over HTTPS, connections to backend data stores are encrypted, and stored data, including every uploaded document, is encrypted at rest.
Extra protection for sensitive fields
Bank account details and tax identifiers receive an additional layer of application-level AES-256 encryption before they are stored, on top of storage-level encryption.
Managed encryption keys
Encryption keys are tenant-scoped and managed through a dedicated cloud key management service, with key usage logged.
Your data is isolated and access is scoped
Tenant data isolation is enforced in the database layer in addition to application-level authorization, and role-based controls limit what each user can see and do.
Tenant data isolation
Each organization's data is isolated using database-enforced controls, so isolation between customers does not depend on application code alone.
Granular role-based access
Five distinct admin roles let you control exactly who can do what: Owner, Admin, Ops, Finance, and Auditor. Access to full payment details is limited to designated privileged roles.
Step-up authentication for sensitive actions
High-risk operations, like viewing full bank account details or downloading sensitive exports, require re-entering your password even if you're already signed in, and that elevated access expires after a short window.
Scoped API keys
API keys are created with specific, limited permissions and are securely hashed before storage.
Controlled support access
Support sessions are tied to a ticket your team opens, are strictly time-limited, and are recorded in your audit log with the operator's identity and the reason for access.
Multiple layers of identity verification
Admin users, vendor portal users, and API integrations each authenticate in a way designed for how they're actually used.
Managed identity provider
Admin authentication is handled by a dedicated managed identity service, and requests are cryptographically verified.
Multi-factor authentication
MFA is required for privileged admin roles and can be enforced for any admin user. Verification codes are time-limited and attempt-limited.
Session security
Sessions are short-lived, and changing your password revokes active sessions across your devices.
Vendor portal security
Vendors use expiring, vendor-scoped portal links rather than shared credentials, and portal access is checked on the server for every request.
Brute-force protection
Authentication endpoints are rate-limited, and repeated failed attempts are flagged for review.
Defense in depth across the platform
Modern browser protections, safe database access patterns, and layered validation applied consistently across the platform.
Modern browser protections
Application pages are served with a strict Content Security Policy and a full suite of security headers, including HTTPS enforcement, clickjacking protection, and restricted browser permissions.
Safe data access and validation
The application uses parameterized database access and input validation, and outbound webhook destinations are validated before delivery.
Secrets management
Production credentials are managed through dedicated secrets-management controls rather than living in application code.
Cloud-native and monitored
OnComply runs on enterprise-grade cloud infrastructure with separation between public traffic, application workloads, and data storage.
Protected data stores
Databases and caches are not directly reachable from the internet; access flows through the application layer.
Backups and recovery
The database runs on a managed service with high availability, automated backups, and point-in-time recovery.
Security monitoring
Errors, performance, and anomalous behavior are monitored continuously to support reliability and incident response.
A detailed record of what matters
Significant actions in OnComply are recorded in a protected audit log designed to support compliance reviews and investigations.
Protected audit log
Audit records are protected against modification after they are written, giving you a reliable record for compliance reviews and investigations.
Long-term retention
Audit logs are retained for seven years by default.
Broad event coverage
Key actions are recorded with who performed them, what was affected, and relevant context: vendor status changes, document validation decisions, contract signings, payment submissions, exports, failed sign-in attempts, and administrative changes.
Vendor compliance timeline and exports
Each vendor gets a single chronological timeline of status changes, document events, contract activity, and communications, and you can export audit history for your organization or any single vendor at any time. Audit exports are themselves recorded.
AI processing transparency
AI document processing is disclosed up front
Microsoft Azure processes documents for automated extraction and validation. Our Data Processing Agreement explains what Azure receives and Microsoft's training and retention commitments.
Running a security review?
We're happy to support procurement and security assessments. Request additional security documentation, ask follow-up questions, or set up a review call with the team.
Request security documentationResponsible Disclosure
If you discover a security vulnerability in OnComply, please report it to us at support@oncomply.biz. We will acknowledge your report within 24 hours and work with you to understand and address the issue. We do not pursue legal action against researchers acting in good faith.
Please include a description of the vulnerability, steps to reproduce, potential impact, and any suggested remediation. We will keep you informed throughout the investigation.