OhMySaaS OhMySaaS
Trust

Security

Last updated 11 August 2026

Every product we operate runs on the same security baseline. This page describes the controls we apply across the portfolio; product-specific documentation is available to customers on request.

Encryption

TLS 1.2+ for all data in transit, HSTS enforced. Data at rest is encrypted with AES-256. Secrets are held in a managed vault, never in source control.

Access control

Least-privilege, role-based access with mandatory MFA for all staff. Production access is time-bound, logged and reviewed quarterly.

Infrastructure

Hosted in SOC 2 certified US data centres with network isolation, managed firewalls, DDoS protection and a WAF in front of every public endpoint.

Development

Peer-reviewed changes, automated dependency and static analysis scanning in CI, separate staging environments, and no production data in development.

Backups and recovery

Encrypted automated backups with point-in-time recovery, retained 35 days and restore-tested on a scheduled basis.

Monitoring

Centralised logging, anomaly alerting and on-call rotation. Audit logs are retained for 12 months.

Incident response

We maintain a documented incident response plan with defined severity levels and owners. If a security incident affects your data, we will notify affected customers without undue delay — and in any case within 72 hours of confirming impact — with what we know, what we've done, and what you should do.

Vendor management

Every sub-processor is reviewed before onboarding and re-reviewed annually. Written data protection terms are required. The current list is published on our Sub-processors page.

Responsible disclosure

Found a vulnerability? Email hello@ohmysaas.com with steps to reproduce. Please give us reasonable time to fix it before publishing, avoid accessing data that isn't yours, and don't run denial-of-service or automated scanning against production. We acknowledge reports within two business days and will credit you if you'd like.