Security & Compliance
The customer onboarding platform with enterprise-grade protection
At OnRamp, security, data protection, and compliance are our top priorities. Our commitment to safeguarding your data is built into every feature, backed by a team with deep experience in developing secure solutions.
Protected to the highest industry standards
Security built in, not bolted on
We undergo continuous, independent audits to meet the most rigorous industry standards, ensuring compliance through robust security and privacy measures.
Our platform is monitored by hundreds of daily automated tests, guaranteeing that our application and security practices meet compliance requirements at all times.
Our certifications and compliance include SOC 2 Type 2 certification, GDPR compliant, HIPAA compliant.
OnRamp is hosted exclusively on AWS, leveraging AWS's robust control environment and certifications, including SSAE-16 SOC 1, 2, & 3, and ISO 27001, to ensure top-tier security and compliance.
Beyond the AWS protections, OnRamp leverages industry leading best practices in Engineering, DevOps, and InfoSec that help us offer comprehensive protection.
With 99.9% uptime, our network and perimeter protections are designed to provide a secure, reliable platform for our customers.
- Logical tenant separation: Each customer's data is securely segmented.
- Encryption in transit: Protects data during transfer using TLS 1.2 and TLS 1.3.
- Encryption at rest: Safeguards stored data with AES-256 encryption.
- Self-hosted data storage: Ensures data availability and control within a secure environment.
OnRamp employs a Test-Driven Development (TDD) approach, combining manual and automated security checks aligned with OWASP application security standards.
This approach ensures rigorous protection through layered, proactive controls, including defense-in-depth strategies, positive security models, secure fail mechanisms, and least-privilege principles.
Our application security measures include:
-
Defense In Depth approach leveraging Firewalls, SIEM, and active Threat Monitoring.
-
DDoS protections: Mitigates distributed denial-of-service attacks to maintain service availability.
-
Regular vulnerability scanning: Identifies and addresses potential weaknesses.
-
Annual penetration testing: Ensures robust security through simulated attack scenarios.
Access to systems is secured with two-factor authentication, rigorously logged, and controlled by least-privilege principles.
Key organizational security measures include:
- Security education & awareness training: Regular training ensures all employees are informed of the latest security best practices.
- 24/7 monitoring and incident response: Continuous monitoring allows rapid detection and response to any security incidents.
- Vendor risk management: Proactive assessment and oversight of third-party vendors safeguard the integrity of our operations.
Core security, privacy and compliance feature
Standard SSL Certificate
Protect your data with secure SSL encryption across all OnRamp pages.
Protected Portal
Ensure secure access to your Customer Portal with authentication restricted to an email whitelist that you control.
Single sign-on (SSO) credentials
Enable users to access OnRamp seamlessly with single sign-on credentials.
Custom Domain Security Settings
Allow your IT teams to control and manage security settings for your Customer Portal.
Audit Logs
Gain visibility into all activity with comprehensive audit trails for your organization.