Security
Effective 2026-08-10

Security and privacy are fundamental to how Onedash is designed. We use technical, organisational, and administrative safeguards intended to protect customer information and reduce the risk of unauthorised access, loss, misuse, alteration, or disclosure. Onedash combines local processing with secure cloud services where required. Where data is transmitted to Onedash infrastructure, we use appropriate encryption and access controls designed to protect information during transmission and storage.

Our security practices continue to evolve alongside the Services, changes in technology, emerging threats, and applicable legal and regulatory requirements.

1. Security Practices

1.1 Encryption

Onedash uses encryption appropriate to the relevant Service and type of information being processed. Measures may include encryption of information in transit, encryption of stored data, encrypted local application databases, application-level encryption for synchronised information, and managed encryption keys.

Where Onedash manages encryption keys to support operation or recovery of a Service, we do not describe that Service as zero-knowledge or end-to-end encrypted unless the technical design of that specific Service supports that description.

1.2 Local Processing

Certain Onedash features are designed to process information locally on the user's device. Information that remains entirely local is not transmitted to Onedash merely because it is processed through the Onedash Application. Local processing can reduce the amount of information that needs to be transmitted to cloud infrastructure and helps limit unnecessary exposure of customer information.

1.3 Access Controls

Access to production systems and customer information is restricted to authorised personnel and systems where access is reasonably required for operational, support, security, or legal purposes. Administrative and privileged access is subject to additional authentication and access controls where appropriate.

1.4 Authentication

Onedash supports account security measures including secure authentication, multi-factor authentication, and passkeys where available. Customers are responsible for maintaining the security of their own credentials, devices, recovery methods, and authorised users.

1.5 Security Monitoring

We maintain operational, administrative, and security logging where appropriate to help detect suspicious activity, investigate incidents, troubleshoot technical issues, and maintain the security and reliability of the Services.

2. Infrastructure and Availability

Onedash uses a combination of Onedash-operated infrastructure and third-party infrastructure and service providers to deliver the Services. We select infrastructure and service providers having regard to security, reliability, availability, privacy, and the requirements of the Services they support. Where applicable, we use backup, recovery, redundancy, monitoring, and restoration procedures designed to support service availability and recovery from operational failures.

No system or service can guarantee uninterrupted availability or complete protection against every security threat, and our security measures are intended to reduce and manage those risks.

3. Security Assurance

Onedash is continuing to develop its security and compliance programme as the platform grows. We do not currently represent Onedash as SOC 2 certified and have not yet completed an independent penetration test of the production platform. Independent security testing, external assessments, and formal compliance certifications may be introduced as the Services and our compliance requirements develop.

We will only publish or represent a certification, assessment, audit, or compliance status once the applicable process has been completed and that representation can be properly supported.

4. Healthcare and Sensitive Information

Onedash may provide features suitable for customers that handle sensitive information, including healthcare-related information. Customers must not use Onedash to process protected health information subject to the United States Health Insurance Portability and Accountability Act ("HIPAA") unless Onedash has expressly authorised that use and an applicable Business Associate Agreement has been entered into between Onedash and the customer.

The availability of security features within Onedash does not by itself mean that a customer's use of the Services satisfies every regulatory or compliance requirement applicable to that customer.

5. Responsible Disclosure

If you believe you have discovered a security vulnerability or security issue affecting Onedash, please report it directly to us so that we can investigate it responsibly. Please include enough information for us to understand and reproduce the issue where possible, including the affected Service, relevant steps, and any supporting technical information.

Please do not publicly disclose a suspected vulnerability before we have had a reasonable opportunity to investigate and address it. Security reports can be submitted to [email protected].

6. Privacy and Data Protection

Our handling of personal information is governed by our Privacy Policy and, where Onedash processes personal information on behalf of a customer, our Data Processing Addendum. Additional information about our use of artificial intelligence and related data practices is available in our AI Transparency Policy.