Defense in depth,
audit by default.
Every action signed. Every field encrypted. Every access logged. Procurement-grade security posture, built into the product — not a service tier.
What we do, end to end.
Encryption at rest
AES-256 on every Postgres volume, file blob and backup. Keys rotated quarterly via KMS.
Encryption in transit
TLS 1.3 enforced. HSTS preloaded. Certificate transparency monitored.
Signed audit log
Every write captures before → after, signed with Ed25519. Tamper-evident, append-only, exportable.
Tenant isolation
Postgres row-level security per tenant_id. No shared connection ever crosses tenants.
SSO / SAML
Okta, Azure AD, JumpCloud, generic SAML 2.0. SCIM 2.0 user provisioning.
RBAC + field ACL
Roles, scopes and field-level access. Approval chains attached to source transaction.
Backups
Continuous WAL streaming + 35-day PITR. Quarterly restore drills with signed receipts.
Pentest 2x/year
Independent black-box and white-box engagements. Critical findings remediated <72h.
Vulnerability disclosure
Safe-harbor policy. Bounty for verified critical findings via security@oean.ai.
Annual report by independent auditor. Available under NDA.
Certification in progress · expected Q3 2026.
Data Processing Addendum (DPA) signed on request.
Optional tenant residency in mainland-CN region.
Request security documents.
SOC 2, pentest summaries, DPA, sub-processor list, and architecture diagrams — sent within one business day under NDA.