Onboardin5 handles the most sensitive moment in your client relationship, the moment they hand you their information. Here is how we protect it, end to end.
Every firm’s data is walled off by row-level security, enforced at the database itself and verified automatically on every release. No firm can ever read another firm’s records.
Data is encrypted in transit with TLS and HSTS, and the most sensitive fields are encrypted at rest with AES-256. Keys are held in a secrets store, never in the codebase.
Every account is protected by TOTP two-factor authentication, required by default, with an AAL2 gate in front of the app. Trusted-device sessions reduce friction without lowering the bar.
Each firm has its own independent signing secrets. Nothing is shared platform-wide, and secrets are never exposed to firm users, only to the service that needs them.
Every meaningful read and write is recorded in an append-only audit log tied to firm, actor, and action, so there is always a clear record of who did what and when.
Daily encrypted backups, with point-in-time recovery available, so a mistake or an incident never means lost data.
Every automated hand-off to your downstream tools is cryptographically signed and sent over TLS, so the systems on the other end can trust it genuinely came from your firm.
Onboardin5 runs on SOC 2 compliant cloud infrastructure and is developed against controls informed by NIST SP 800-53. This page describes controls in place, it is not a certification or legal advice.
This page summarizes the security controls in place for the Onboardin5 platform. It is provided for information and is not a certification, warranty, or legal advice. For your IT or compliance team’s specific questions, reach out and we will walk them through it.
We are happy to walk your team through data isolation, encryption, and our incident process before you commit to anything.
Book a security walkthrough