TRUST CENTER
Security at Onbrand
Trusted by thousands of product development professionals every day to protects sensitive product and IP data around the clock. Regular audits, automated backups, and robust authentication practices give teams peace of mind, ensuring both operational efficiency and enterprise-grade security compliance.

In Progress

Pending

2027
Authentication
Onbrand allows organizations to enable OAuth identity providers, as well as SAML 2.0 authentication providers such as Okta, to support single sign-on (SSO). SSO helps strengthen account security by allowing users to authenticate through their organization’s trusted identity provider.
SSO is available on Enterprise plans only.
Data Encryption
All customer data is encrypted at rest with AES-256 and in transit via TLS.
Sensitive information like access tokens and keys are encrypted at the application level before they are stored in the database.
SOC 2
Onbrand is currently undergoing a SOC 2 Type 2 audit. This process supports our commitment to maintaining strong security controls for handling sensitive customer data.
Once the audit is complete, enterprise customers will be able to access our SOC 2 Type 2 report through the Onbrand Trust Center.
ISO27001
Onbrand is pending our ISO27001 compliance certification. This is an important security policy when handling sensitive customer data.
Enterprise customers can access our ISO report from our trust center.
GDPR
Onbrand is not currently GDPR certified, but we maintain privacy and data protection practices aligned with GDPR principles for handling customer personal data.
Enterprise customers may access our policy & security documentation through the Onbrand Trust Center.
Backups
All customer databases are backed up every day. Point in Time Recovery allows restoring the database to a psicific point in time.
Customers with Pro and Enterprise Plans have there recovery timelines described in the SLA.
Vulnerability Management
Onbrand works with industry experts to conduct regular penetration tests.
In addition to internal security reviews, we use various tools to scan our code for vulnerabilities including GitHub, Delve, and Sentry.
DDoS Protection
Onbrand combats Distributed Denial of Service attacks in several ways to mitigate resource abuse with protections at the CDN level via Cloudflare,


