Trust Center
Security at Onwork
Onwork is operated by Oncode S.r.l., an ISO/IEC 27001-certified Italian company. Our security programme is built on the same Information Security Management System (ISMS) used across the Oncode group, and tailored to the specific risks of HR/operations data.
- Version
- v1.0
- Effective
- 2026-04-25
Certifications and frameworks
- ISO/IEC 27001 — Oncode S.r.l. is certified for its Information Security Management System.
- ISO 9001 — Quality management.
- GDPR — full alignment, ISO 27701 controls applied.
- NIS2 readiness — assessed against Italian Legislative Decree 138/2024.
- SOC 2 Type I/II — on the roadmap (target 2027).
Hosting and data residency
Onwork runs on AWS eu-west-1 (Ireland). All customer data is stored within the EU. MongoDB replica sets are deployed in EU regions with synchronous replication. Customer-specific data residency (e.g. Italy region) is available for Enterprise plans on request.
Encryption
- In transit: TLS 1.3 with strong cipher suites, HSTS, secure cookies.
- At rest: AES-256 at the storage layer (S3, MongoDB, EBS volumes).
- Secrets: managed via HashiCorp Vault with rotation and audit logging.
Authentication and access control
- Strong password policy and account lockout protections.
- Multi-factor authentication (MFA) available for admins.
- Role-based access control (RBAC) with granular permissions.
- Short-lived JWT tokens with refresh rotation.
- SSO/SAML and SCIM provisioning on the roadmap.
Auditing and observability
All write and security-relevant operations are recorded in an immutable audit log with before/after states, actor, timestamp and request context. Operational telemetry (metrics, logs, traces, profiles) is collected via OpenTelemetry into a self-hosted Grafana stack (Loki, Tempo, Pyroscope).
Backup and disaster recovery
Daily snapshots are stored in encrypted form in a separate AWS account, with a default retention of 30 days. We aim for an RPO of 24 hours and an RTO of 4 hours. Backup restore drills are performed periodically.
Secure development lifecycle
- Code review required for every change.
- Static and dynamic analysis (SAST/DAST) integrated in CI/CD.
- Dependency scanning and software bill of materials (SBOM).
- Security training for engineering team.
- Threat modelling for major features.
Vulnerability management and penetration tests
We run continuous vulnerability scanning on dependencies and container images. An annual third-party penetration test covers web app, API and infrastructure. Critical findings are remediated according to documented SLAs (Critical: 7 days; High: 30 days; Medium: 90 days).
Incident response
We follow a documented incident-response playbook with on-call rotation, severity classification, internal communication channels and post-mortems. In case of a personal data breach, customers are notified within 24 hours per the DPA.
Vulnerability disclosure
If you believe you have found a security issue, please email [email protected]. We acknowledge reports within 2 business days. We do not currently run a public bug-bounty programme; responsible disclosure is welcomed.
Security documents
- Security Policy (ISO-style)
- Data Processing Agreement
- Sub-processors list
- Security Whitepaper (PDF — on request)
- Pen test executive summary (PDF — under NDA)