Users & partners
MFA · RBACAccess linked to role and scope
Review hosting, access controls and data protection. Scope and responsibilities are detailed in your project documentation.
Access linked to role and scope
Protected data and documents
Documented controls
Scope, controls and responsibilities are detailed in the security documentation.
OneChain maintains a documented ISMS, a security assurance plan and a risk assessment. ISO 27001 or SOC 2 certification has not been obtained yet.
Critical services use MFA. The application enforces roles and access controls by organization and user scope.
Core operational data is hosted on AWS eu-west-1. Encryption is enabled in transit and at rest on managed services.
The recovery plan covers application, database and documents with automated backups and staging restore tests.
Dependencies, containers, secrets, cloud posture and SBOM are monitored by automated tools with remediation SLA by severity.
Datadog EU, CloudTrail, CloudWatch and GuardDuty cover internal observability. Customer SIEM export is not offered by default.
Certifications. ISO 27001, SOC 2, CSA STAR and CRA are not certified yet. Practices are documented and certification is on the roadmap.
Optional AI. AI features use OpenAI APIs under Standard Contractual Clauses, data minimization and a no-PII policy. They can be discussed or disabled for customers requiring strict residency.
Isolation. Isolation is logical at application level through clientId, roles and GraphQL controls. OneChain does not provide dedicated per-customer LLM instances.
SIEM and exports. Log exports to a customer SIEM are not standard. They are handled through a dedicated contractual agreement.
Tell us which documents and questions your IT team would like to review.