Security & data protection at Onspring
Data security is of utmost importance to our business and that of our customers. We take our security and compliance measures seriously, so you can rest easy knowing Onspring works tirelessly to maintain our security and your trust.
Onspring Platform Certifications
SOC2 Type II
Onspring maintains a SOC2 Type II attestation annually with AICPA to validate our safeguards for customer data security, availability & confidentiality.
CSA & CCM
Onspring is STAR Level One with the Cloud Security Alliance (CSA), demonstrating our continued compliance with the Cloud Controls Matrix (CCM).
FedRAMP Authorized
Onspring GovCloud is FedRAMP Authorized at a moderate impact level.
View GSA Listing.
Penetration Attestations
Network penetration tests against public-facing infrastructure and web app tests against public-facing web services, plus internal vulnerability and penetration testing against non-public infrastructure, including wireless networks, is conducted annually.
IT Accessibility/Section 508
Onspring ensures the accessibility and usability of our platform and products for individuals with disabilities through our compliance with the Voluntary Product Accessibility Template (VPAT) v2.4 and revised 508 standards.
Subservice Organizations
Subservice organizations maintain their own certifications and audit processes that meet the requirements of their service offerings. Onspring reviews attestations annually to ensure their due diligence activities and our mandatory requirements.
Policies & Procedures
We document information privacy, security, and risk management policies to ensure the confidentiality, integrity, and availability of customer data. Clearly defined roles, responsibilities, policies, and procedures protect the data stored in Onspring.
Security practices:
- Maintenance of Information Security Policies
- Dedicated security resources with defined responsibilities and accountability
- Acceptable use of Onspring’s platform and systems
- Identity, access, and authentication management
- Access control and password requirements
- Platform logging and monitoring process
- Incident response process
- Risk management, certifications, and assessments
- Physical controls and security requirements of our data centers
- Third-party risk management, security, and privacy
FAQS
Data security is our priority. We take testing seriously and we take proactive data protection even more seriously.
SecurityScorecard awarded Onspring with a 100/100 score.
If you have additional questions please reach out to us to discuss.