Security at OneStack

At OneStack, we take security seriously. We understand the importance of protecting our customers' data and ensuring the highest levels of privacy and security. Our security practices are designed to meet the stringent requirements of SOC 2 and industry best practices.

Network Security

We employ a private network to connect our backend and frontend services, significantly reducing the chances of unauthorised access. Our infrastructure is protected behind Cloudflare and reverse proxies, providing an additional layer of security.

Encryption and Access Control

All passwords are encrypted using the industry-standard bcrypt algorithm, ensuring that sensitive user credentials are never stored in plain text. Our access control mechanisms follow the principle of least privilege, granting users only the necessary permissions to perform their required tasks.

Infrastructure Security

Our current infrastructure leverages Virtual Private Servers (VPSs) with a secure virtual network connecting our services. As we grow, we plan to transition to dedicated servers and eventually run our own servers, providing even greater auditability and transparency.

Open-Source and Transparency

As an open-source platform, we are committed to transparency and making our infrastructure and security practices openly available for scrutiny. Our goal is to foster trust and confidence in our security measures by embracing openness and collaboration.

Continuous Improvement

Security is an ongoing process, and we are dedicated to continuously improving our security posture. We regularly review and update our practices, staying abreast of the latest threats and industry best practices to ensure the highest levels of protection for our customers.