Trust Center

SOC 2-aligned controls program

Self-assessed controls mapped to SOC 2 Trust Services Criteria (Security & Confidentiality). This is not an audit opinion, attestation, certification, or claim of SOC 2 compliance.

Independent attestation: planned

TSC scope

Security · Confidentiality

Deferred

Availability · Processing Integrity · Privacy

Last reviewed

2026-08-25

Controls summary

Status reflects what is real in production today, what is planned automation, and what remains founder-manual. No aspirational "green" without evidence.

ControlTSCStatusEvidence
GOV-1Security officer designated
Named individual accountable for security program decisions.
CC1.1, CC1.2ImplementedMANUAL
GOV-2Policy set approved and reviewed annually
Core security policies exist, versioned, with approval line.
CC1.2, CC2.2PlannedMANUAL
GOV-3Security contact published
Public security contact and disclosure intake path.
CC2.2, CC2.3Implementedautomated
RSK-1Annual risk assessment
Documented annual risk assessment covering key threats and treatments.
CC3.1, CC3.2PlannedMANUAL
VND-1Subprocessor register current
Register of critical subprocessors stays aligned with published security doc.
CC9.2Implementedautomated
VND-2Critical-vendor attestation review
Periodic review of critical vendor SOC/ISO public attestation pages.
CC9.2Plannedautomated
ACC-1MFA on Meridian and admin surfaces
Meridian API requires TOTP enrollment and fresh Firebase totp_verified_at claim.
CC6.1, CC6.2Implementedautomated
ACC-2Least-privilege access review
Monthly snapshot of privileged principals across GitHub, Render, Vercel, Firebase, Tiger.
CC6.2, CC6.3Plannedautomated
ACC-3Offboarding
Access removal process for departing personnel.
CC6.2ImplementedMANUAL
ACC-4Customer data isolation
Org-scoped queries and KMS AAD binding for vendor credentials.
CC6.1Implementedautomated
ENC-1Encryption at rest for sensitive credentials
Vendor/billing credentials encrypted with KMS envelope + per-org AAD.
CC6.1, CC6.7Implementedautomated
ENC-2TLS in transit
Public endpoints serve HTTPS with modern TLS.
CC6.7Plannedautomated
ENC-3Email authentication
SPF, DKIM, DMARC for onaro.io (and brianonai.com where applicable).
CC6.7Plannedautomated
ENC-4Secrets management
No hardcoded secrets in repositories; Secret Manager / Action secrets for runtime.
CC6.1Plannedautomated
OPS-1Change management via PR review
Production changes ship through GitHub PRs with founder review.
CC8.1Implementedautomated
OPS-2Vulnerability management
Dependency vulnerability scanning with patch decisions for critical/high.
CC7.1Plannedautomated
OPS-3Logging and monitoring
Admin audit logs and operational Slack alerts.
CC7.2Implementedautomated
OPS-4Backups and recovery
Tiger Cloud automated backups; annual restore test.
CC7.5Plannedmixed
OPS-5Incident response plan and register
Written IR plan and dated incident register (empty OK).
CC7.3, CC7.4PlannedMANUAL
OPS-6Security headers and CSP
Production CSP and security headers match approved baseline.
CC7.1Implementedautomated
CON-1Data retention and deletion enforced
Retention policies and deletion pathway for customer data.
C1.1, C1.2Plannedautomated
CON-2Customer data handling commitments
Customer agreement and security doc align on handling commitments.
C1.1ImplementedMANUAL

Architecture (security-relevant)

  • Read-only metering toward customer production systems.
  • Vendor credentials encrypted with KMS envelope encryption and per-org AAD.
  • Meridian APIs require Firebase identity plus TOTP claim (≤24h).
  • Org-scoped data access; admin actions audited.
  • Details: Docs · security@onaro.io

Subprocessors

Current infrastructure and business tools that may process Onaro or customer data.

ProviderFunctionCritical
Firebase / Google CloudAuthentication; KMS; Secret ManagerYes
VercelOnaro web hostingYes
RenderMFA backend and product API hostingYes
Tiger Cloud (TimescaleDB)Meridian spend databaseYes
Cloudflare R2Object storage for uploadsYes
Redis (managed)Celery job queueNo
ResendTransactional email (notifications@onaro.io)Yes
Microsoft 365Operator productivity / emailNo
HubSpotCRM / sales pipelineNo
SlackInternal notificationsNo
Google Analytics / GTMWebsite analytics (marketing)No

Request the Security Controls Report

Quarterly customer-facing PDF: controls summary, architecture, subprocessors, and the same disclaimer — the questionnaire upgrade from "No SOC 2" to a documented controls program with evidence collection. Formal attestation remains planned.

Or email security@onaro.io.