✨ OONH — the Smart Execution Layer for MSMEs — See what's new
Pricing
Book a Demo Sign in Book a Demo →
SECURITY

Security at OONH

Enterprise-grade protection for your business data

1. Infrastructure 2. Encryption 3. Tenant Isolation 4. Access Control 5. API Security 6. Audit Trail 7. Incident Response 8. Third-Party 9. Vulnerability Mgmt 10. Contact

1Infrastructure

Secure cloud infrastructure with automated failover, daily encrypted backups retained 30 days. All servers are firewalled with restricted SSH access and automated security patching.

2Encryption

At rest: AES-256 for all data and backups. In transit: TLS 1.3 on all connections. Secrets: API keys, OAuth tokens stored in encrypted columns with application-layer decryption.

3Tenant Isolation

Every workspace is isolated. All queries scoped by tenant_id. Sessions, uploads, API keys, automation rules — all tenant-scoped. Cross-tenant access architecturally impossible.

4Access Control

RBAC: 4 roles with per-module, per-action granularity. Sessions: Server-side, HttpOnly cookies, inactivity expiry. Passwords: bcrypt + salt, email-verified reset.

5API Security

Auth via X-Internal-Key or session token. 100 req/min rate limit. All access logged. Keys scoped per module, revocable.

6Audit Trail

Every critical action logged with timestamp, user, IP, action, entity. Retained 12 months, tamper-resistant.

7Incident Response

SLAs: Critical (1h), High (4h), Medium (24h). Customer notification within 72h of confirmed breaches.

8Third-Party

Only established providers: Razorpay (PCI-DSS), Meta (SOC 2), Cloudinary (SOC 2), Resend. Minimum-data principle.

9Vulnerability Mgmt

Dependency CVE monitoring. Input validation, output encoding (XSS/SQLi). CSRF on all forms. Uploads type-checked, stored outside web root.

10Contact

Report vulnerabilities: [email protected]. Acknowledged within 24h, resolution timeline within 72h.