01 / security

Defense in depth,
audit by default.

Every action signed. Every field encrypted. Every access logged. Procurement-grade security posture, built into the product — not a service tier.

SOC 2 Type II · pentest 2x/year · 24/7 on-call
02/Controls

What we do, end to end.

S-01

Encryption at rest

AES-256 on every Postgres volume, file blob and backup. Keys rotated quarterly via KMS.

S-02

Encryption in transit

TLS 1.3 enforced. HSTS preloaded. Certificate transparency monitored.

S-03

Signed audit log

Every write captures before → after, signed with Ed25519. Tamper-evident, append-only, exportable.

S-04

Tenant isolation

Postgres row-level security per tenant_id. No shared connection ever crosses tenants.

S-05

SSO / SAML

Okta, Azure AD, JumpCloud, generic SAML 2.0. SCIM 2.0 user provisioning.

S-06

RBAC + field ACL

Roles, scopes and field-level access. Approval chains attached to source transaction.

S-07

Backups

Continuous WAL streaming + 35-day PITR. Quarterly restore drills with signed receipts.

S-08

Pentest 2x/year

Independent black-box and white-box engagements. Critical findings remediated <72h.

S-09

Vulnerability disclosure

Safe-harbor policy. Bounty for verified critical findings via security@oean.ai.

03/Compliance
Standard
SOC 2 Type II

Annual report by independent auditor. Available under NDA.

Standard
ISO 27001

Certification in progress · expected Q3 2026.

Standard
GDPR & PDPA

Data Processing Addendum (DPA) signed on request.

Standard
China data residency

Optional tenant residency in mainland-CN region.

Request security documents.

SOC 2, pentest summaries, DPA, sub-processor list, and architecture diagrams — sent within one business day under NDA.