Skip to main content
Skip to main content
Trust isn't a logo wall

Real operations, live status, public postmortems.

Everything we tell prospective customers about how OneAce operates — encryption, access control, resilience, incidents — in one place, updated as the system evolves. No NDA required for the summary below.

See /status
Uptime · rolling 90-day average
Live data
< 200ms
p50 API latency
Production target
0
P0 incidents · trailing 12 months
See incident log
RPO 5m / RTO 45m
Recovery objective
Tested quarterly

Headline numbers are commitments and live-system readings, not marketing claims — visit /status for the source-of-truth uptime feed.

How we operate

The five pillars.

Plain-English summary of what a CISO will see in a security questionnaire. Detail behind each bullet lives in our internal security documentation — available under NDA from sales.

Data protection

Encryption at rest (AES-256) and in transit (TLS 1.3). Per-tenant row-level isolation enforced at the database. Quarterly key rotation cadence.

  • AES-256 at rest
  • TLS 1.3 in transit
  • Tenant row-level isolation
  • Quarterly key rotation

Access control

SSO via SAML 2.0 / OIDC, SCIM provisioning, and TOTP 2FA on every Enterprise seat. Capability-based authorization gates every server action.

  • SAML 2.0 & OIDC
  • SCIM 2.0 provisioning
  • Mandatory TOTP 2FA
  • Capability-based auth

Audit & logging

Every state-changing action is logged with actor, before/after diff, and request id. Retention defaults to 13 months; Enterprise extends to 7 years with SIEM export.

  • Full audit trail
  • 13-month retention
  • SIEM export (webhook / S3)
  • Tamper-evident chain

Resilience

Multi-region active-passive on managed Postgres. Recovery objectives are tested — not assumed. The disaster runbook is published, not stored in a drawer.

  • Multi-region failover
  • RPO 5m / RTO 45m target
  • Quarterly DR drills
  • Public runbook

Vendor management

Sub-processor list is public and versioned. Customers receive advance notice on additions, with flow-down DPAs in place for every vendor.

  • Public sub-processor list
  • 30-day change notice
  • Flow-down DPAs
  • Annual vendor review
Sub-processors

Who we share data with.

For change notifications, contact trust@oneace.app.

Privacy details
VendorPurposeData sharedRegion
VercelApplication hosting & CDNRequest metadata, cached assetsGlobal edge
Neon (Postgres)Primary databaseAll customer inventory dataEU-West-2 (London)
StripeBilling & invoicingAccount & billing contactUSA / EU
ResendTransactional emailEmail addresses, message bodiesUSA / EU
PostHogProduct analytics (no PII)Anonymized event streamEU-Central-1
SentryError monitoringStack traces, request idsUSA
CloudflareWAF, DDoS, bot protectionPublic request metadataGlobal
Incident commitment

When something breaks.

The public status page is updated within 15 minutes of detection. A written postmortem is published within 5 business days for every Sev-2 or worse. Customer communication is the on-call engineer's first job, not a comms-team afterthought.

Trailing 12 months: 0 incidents with customer data impact. Severity-2 events and resolutions are on the right, with full timelines on /status.

Recent incidents · public log

2026-03-18
Webhook delivery delays — EU region
42 min · queue saturation · workers re-sized, alert threshold tightened.
P2
2026-01-22
Search latency spike — Reports module
28 min · slow query on aggregated movements · index added, query plan pinned.
P2
2025-11-04
Mobile scanner crash — Android 14 only
3 h · OS-specific regression · hot-fix shipped via Play Store internal track.
P3

Policies & legal

Trust commitments above are grounded in our written policies — everything OneAce customers sign or rely on is linked here.

Contact the trust team

Security questionnaires, DPA requests, and vulnerability reports route through one inbox. We acknowledge within one business day.

trust@oneace.appsecurity@oneace.app · vuln disclosure

Cookie preferences

We use essential cookies to make this site work, plus optional cookies for preferences and analytics. You can change your choice anytime via the privacy policy. Read our privacy policy.