Security built into every layer
Oneprofile encrypts data at rest and in transit, runs on Google Cloud, and gives your team full control over access and permissions.
Security controls you manage
Oneprofile gives your team the tools to enforce your organization's security policies directly in the product.

Feature 1
SSO & MFA
Sign in with your identity provider via SAML or OIDC. Multi-factor authentication adds a second layer of protection for every account.

Feature 2
Audit logs
Every action in Oneprofile is logged with user attribution, timestamp, and details. Available on Team and Enterprise plans.

Feature 3
Credential validation
Oneprofile validates API credentials on connect and alerts you if credentials expire or are revoked. No silent sync failures.

Feature 4
Error recovery
Failed records are captured with full error context so you can inspect, fix, and retry. No data is silently dropped.
Infrastructure security
Oneprofile runs on Google Cloud Platform with encryption at every layer. We follow least-privilege access principles and regularly review our security posture.
Encryption everywhere
All data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Credentials are stored in a dedicated secrets manager, never in application databases.
Network isolation
Production systems run in isolated VPCs with strict ingress/egress rules. Internal services communicate over private networks only.
Monitoring and alerting
Automated monitoring detects anomalies in real time. Security events are logged, reviewed, and escalated through defined incident response procedures.
Data residency
Oneprofile runs multi-region infrastructure so your data stays close to your users. Contact us to discuss data residency requirements for your organization.
Compliance
Oneprofile meets the data privacy and compliance requirements that security-conscious teams expect.
GDPR
Oneprofile processes data in accordance with GDPR requirements. A Data Processing Agreement is available for all customers on request.
CCPA
Oneprofile respects California Consumer Privacy Act requirements. Customers can request data access, deletion, and opt-out of data sale. We never sell customer data.
SOC 2
On Roadmap
We are currently working towards SOC II Type 2 compliance to ensure the highest standards of security, availability, processing integrity, confidentiality, and privacy.
Data privacy
Oneprofile stores your data to deduplicate records, sync only what changed, and power profile search and activity logs. Activity logs follow your plan's retention period. Profiles and sync state are kept until you delete the sync or integration.
We do not sell, share, or use customer data for any purpose beyond providing the service.