Trust Center
SOC 2-aligned controls program
Self-assessed controls mapped to SOC 2 Trust Services Criteria (Security & Confidentiality). This is not an audit opinion, attestation, certification, or claim of SOC 2 compliance.
Independent attestation: planned
TSC scope
Security · Confidentiality
Deferred
Availability · Processing Integrity · Privacy
Last reviewed
2026-08-25
Controls summary
Status reflects what is real in production today, what is planned automation, and what remains founder-manual. No aspirational "green" without evidence.
| Control | TSC | Status | Evidence |
|---|---|---|---|
GOV-1 — Security officer designated Named individual accountable for security program decisions. | CC1.1, CC1.2 | Implemented | MANUAL |
GOV-2 — Policy set approved and reviewed annually Core security policies exist, versioned, with approval line. | CC1.2, CC2.2 | Planned | MANUAL |
GOV-3 — Security contact published Public security contact and disclosure intake path. | CC2.2, CC2.3 | Implemented | automated |
RSK-1 — Annual risk assessment Documented annual risk assessment covering key threats and treatments. | CC3.1, CC3.2 | Planned | MANUAL |
VND-1 — Subprocessor register current Register of critical subprocessors stays aligned with published security doc. | CC9.2 | Implemented | automated |
VND-2 — Critical-vendor attestation review Periodic review of critical vendor SOC/ISO public attestation pages. | CC9.2 | Planned | automated |
ACC-1 — MFA on Meridian and admin surfaces Meridian API requires TOTP enrollment and fresh Firebase totp_verified_at claim. | CC6.1, CC6.2 | Implemented | automated |
ACC-2 — Least-privilege access review Monthly snapshot of privileged principals across GitHub, Render, Vercel, Firebase, Tiger. | CC6.2, CC6.3 | Planned | automated |
ACC-3 — Offboarding Access removal process for departing personnel. | CC6.2 | Implemented | MANUAL |
ACC-4 — Customer data isolation Org-scoped queries and KMS AAD binding for vendor credentials. | CC6.1 | Implemented | automated |
ENC-1 — Encryption at rest for sensitive credentials Vendor/billing credentials encrypted with KMS envelope + per-org AAD. | CC6.1, CC6.7 | Implemented | automated |
ENC-2 — TLS in transit Public endpoints serve HTTPS with modern TLS. | CC6.7 | Planned | automated |
ENC-3 — Email authentication SPF, DKIM, DMARC for onaro.io (and brianonai.com where applicable). | CC6.7 | Planned | automated |
ENC-4 — Secrets management No hardcoded secrets in repositories; Secret Manager / Action secrets for runtime. | CC6.1 | Planned | automated |
OPS-1 — Change management via PR review Production changes ship through GitHub PRs with founder review. | CC8.1 | Implemented | automated |
OPS-2 — Vulnerability management Dependency vulnerability scanning with patch decisions for critical/high. | CC7.1 | Planned | automated |
OPS-3 — Logging and monitoring Admin audit logs and operational Slack alerts. | CC7.2 | Implemented | automated |
OPS-4 — Backups and recovery Tiger Cloud automated backups; annual restore test. | CC7.5 | Planned | mixed |
OPS-5 — Incident response plan and register Written IR plan and dated incident register (empty OK). | CC7.3, CC7.4 | Planned | MANUAL |
OPS-6 — Security headers and CSP Production CSP and security headers match approved baseline. | CC7.1 | Implemented | automated |
CON-1 — Data retention and deletion enforced Retention policies and deletion pathway for customer data. | C1.1, C1.2 | Planned | automated |
CON-2 — Customer data handling commitments Customer agreement and security doc align on handling commitments. | C1.1 | Implemented | MANUAL |
Architecture (security-relevant)
- Read-only metering toward customer production systems.
- Vendor credentials encrypted with KMS envelope encryption and per-org AAD.
- Meridian APIs require Firebase identity plus TOTP claim (≤24h).
- Org-scoped data access; admin actions audited.
- Details: Docs · security@onaro.io
Subprocessors
Current infrastructure and business tools that may process Onaro or customer data.
| Provider | Function | Critical |
|---|---|---|
| Firebase / Google Cloud | Authentication; KMS; Secret Manager | Yes |
| Vercel | Onaro web hosting | Yes |
| Render | MFA backend and product API hosting | Yes |
| Tiger Cloud (TimescaleDB) | Meridian spend database | Yes |
| Cloudflare R2 | Object storage for uploads | Yes |
| Redis (managed) | Celery job queue | No |
| Resend | Transactional email (notifications@onaro.io) | Yes |
| Microsoft 365 | Operator productivity / email | No |
| HubSpot | CRM / sales pipeline | No |
| Slack | Internal notifications | No |
| Google Analytics / GTM | Website analytics (marketing) | No |
Request the Security Controls Report
Quarterly customer-facing PDF: controls summary, architecture, subprocessors, and the same disclaimer — the questionnaire upgrade from "No SOC 2" to a documented controls program with evidence collection. Formal attestation remains planned.