Data Protection

Tenant Isolation

Every customer's data is logically isolated using PostgreSQL Row-Level Security (RLS) policies. Each API request is verified against project ownership before returning any data.

Authentication & Access

Compliance

Onboardics is designed with privacy by default.

GDPR CCPA DPA Available

What We Explicitly Do NOT Have

Not yet in place: SOC 2 Type II certification (targeting Q4 2026), HIPAA BAAs, SAML SSO, customer-facing audit log exports, formal third-party penetration testing. If any of these are blockers for your evaluation, email tyler@onboardics.com and we'll discuss your timeline.

SOC 2 Type II

We are pursuing SOC 2 Type II certification. Our target completion is Q4 2026. In the meantime, the controls described on this page — tenant isolation, encryption, access controls, audit logging, and CI-enforced security checks — reflect the operational practices that SOC 2 evaluates.

If you need a security questionnaire completed before your evaluation, contact tyler@onboardics.com and we'll respond within 48 hours.

Report a Vulnerability

If you discover a security vulnerability in Onboardics, please report it responsibly to tyler@onboardics.com. We take all reports seriously and will respond within 48 hours.

We do not currently offer a formal bug bounty program, but we appreciate and acknowledge responsible disclosures.

Last updated: April 10, 2026