Trust Center

Security is the spine of Onwork.

Every Onwork environment runs on EU infrastructure, under Oncode's ISO 27001-certified ISMS. We treat your operations data — and your employees' data — with the same standards we'd want as a customer.

ISO/IEC 27001ISO 9001GDPRAWS eu-west-1MongoDB EUHashiCorp Vault
ISO 27001
Certified ISMS
EU only
Data residency
TLS 1.3
In transit + at rest
24h
Breach notification SLA

Trust Center

Security at Onwork

Onwork is operated by Oncode S.r.l., an ISO/IEC 27001-certified Italian company. Our security programme is built on the same Information Security Management System (ISMS) used across the Oncode group, and tailored to the specific risks of HR/operations data.

Version
v1.0
Effective
2026-04-25
Download PDF

Certifications and frameworks

  • ISO/IEC 27001 — Oncode S.r.l. is certified for its Information Security Management System.
  • ISO 9001 — Quality management.
  • GDPR — full alignment, ISO 27701 controls applied.
  • NIS2 readiness — assessed against Italian Legislative Decree 138/2024.
  • SOC 2 Type I/II — on the roadmap (target 2027).

Hosting and data residency

Onwork runs on AWS eu-west-1 (Ireland). All customer data is stored within the EU. MongoDB replica sets are deployed in EU regions with synchronous replication. Customer-specific data residency (e.g. Italy region) is available for Enterprise plans on request.

Encryption

  • In transit: TLS 1.3 with strong cipher suites, HSTS, secure cookies.
  • At rest: AES-256 at the storage layer (S3, MongoDB, EBS volumes).
  • Secrets: managed via HashiCorp Vault with rotation and audit logging.

Authentication and access control

  • Strong password policy and account lockout protections.
  • Multi-factor authentication (MFA) available for admins.
  • Role-based access control (RBAC) with granular permissions.
  • Short-lived JWT tokens with refresh rotation.
  • SSO/SAML and SCIM provisioning on the roadmap.

Auditing and observability

All write and security-relevant operations are recorded in an immutable audit log with before/after states, actor, timestamp and request context. Operational telemetry (metrics, logs, traces, profiles) is collected via OpenTelemetry into a self-hosted Grafana stack (Loki, Tempo, Pyroscope).

Backup and disaster recovery

Daily snapshots are stored in encrypted form in a separate AWS account, with a default retention of 30 days. We aim for an RPO of 24 hours and an RTO of 4 hours. Backup restore drills are performed periodically.

Secure development lifecycle

  • Code review required for every change.
  • Static and dynamic analysis (SAST/DAST) integrated in CI/CD.
  • Dependency scanning and software bill of materials (SBOM).
  • Security training for engineering team.
  • Threat modelling for major features.

Vulnerability management and penetration tests

We run continuous vulnerability scanning on dependencies and container images. An annual third-party penetration test covers web app, API and infrastructure. Critical findings are remediated according to documented SLAs (Critical: 7 days; High: 30 days; Medium: 90 days).

Incident response

We follow a documented incident-response playbook with on-call rotation, severity classification, internal communication channels and post-mortems. In case of a personal data breach, customers are notified within 24 hours per the DPA.

Vulnerability disclosure

If you believe you have found a security issue, please email [email protected]. We acknowledge reports within 2 business days. We do not currently run a public bug-bounty programme; responsible disclosure is welcomed.

Security documents