Security

The information you need for your security review.

Review hosting, access controls and data protection. Scope and responsibilities are detailed in your project documentation.

Illustrative architectureControlled access at every step.

Users & partners

MFA · RBAC

Access linked to role and scope

OneChain TLS · KMS

Protected data and documents

AWS eu-west-1

Core infrastructure

Documented controls

Scope, controls and responsibilities are detailed in the security documentation.

Documented ISMS aligned with market standards

OneChain maintains a documented ISMS, a security assurance plan and a risk assessment. ISO 27001 or SOC 2 certification has not been obtained yet.

  • Weekly security review
  • Certification roadmap planned
  • Stoik cyber insurance
MFA, RBAC and least privilege

Critical services use MFA. The application enforces roles and access controls by organization and user scope.

  • Auth0 and AWS IAM
  • Application roles
  • 15 min session timeout
Encryption and EU hosting for the SaaS core

Core operational data is hosted on AWS eu-west-1. Encryption is enabled in transit and at rest on managed services.

  • TLS 1.2+
  • AWS KMS AES-256
  • Aurora PostgreSQL and S3
Backups, restore testing and recovery targets

The recovery plan covers application, database and documents with automated backups and staging restore tests.

  • App RTO 10 min
  • App RPO 15 min
  • Weekly restore tests
Automated scanning and prioritized remediation

Dependencies, containers, secrets, cloud posture and SBOM are monitored by automated tools with remediation SLA by severity.

  • Snyk, GitGuardian, Trivy
  • ScoutSuite and Datadog SBOM
  • Critical 24-48h
Internal logs and contractual integrations

Datadog EU, CloudTrail, CloudWatch and GuardDuty cover internal observability. Customer SIEM export is not offered by default.

  • Structured internal logs
  • AWS audit trail
  • SIEM export under specific agreement
Scope, AI and responsibilities

Certifications. ISO 27001, SOC 2, CSA STAR and CRA are not certified yet. Practices are documented and certification is on the roadmap.

Optional AI. AI features use OpenAI APIs under Standard Contractual Clauses, data minimization and a no-PII policy. They can be discussed or disabled for customers requiring strict residency.

Isolation. Isolation is logical at application level through clientId, roles and GraphQL controls. OneChain does not provide dedicated per-customer LLM instances.

SIEM and exports. Log exports to a customer SIEM are not standard. They are handled through a dedicated contractual agreement.

Your project

Let’s prepare your security review.

Tell us which documents and questions your IT team would like to review.

Request documentation