Security
Last updated 11 August 2026
Every product we operate runs on the same security baseline. This page describes the controls we apply across the portfolio; product-specific documentation is available to customers on request.
Encryption
TLS 1.2+ for all data in transit, HSTS enforced. Data at rest is encrypted with AES-256. Secrets are held in a managed vault, never in source control.
Access control
Least-privilege, role-based access with mandatory MFA for all staff. Production access is time-bound, logged and reviewed quarterly.
Infrastructure
Hosted in SOC 2 certified US data centres with network isolation, managed firewalls, DDoS protection and a WAF in front of every public endpoint.
Development
Peer-reviewed changes, automated dependency and static analysis scanning in CI, separate staging environments, and no production data in development.
Backups and recovery
Encrypted automated backups with point-in-time recovery, retained 35 days and restore-tested on a scheduled basis.
Monitoring
Centralised logging, anomaly alerting and on-call rotation. Audit logs are retained for 12 months.
Incident response
We maintain a documented incident response plan with defined severity levels and owners. If a security incident affects your data, we will notify affected customers without undue delay — and in any case within 72 hours of confirming impact — with what we know, what we've done, and what you should do.
Vendor management
Every sub-processor is reviewed before onboarding and re-reviewed annually. Written data protection terms are required. The current list is published on our Sub-processors page.
Responsible disclosure
Found a vulnerability? Email hello@ohmysaas.com with steps to reproduce. Please give us reasonable time to fix it before publishing, avoid accessing data that isn't yours, and don't run denial-of-service or automated scanning against production. We acknowledge reports within two business days and will credit you if you'd like.