The Onapsis Trust Center: Enterprise Security and Compliance
The privacy and security of our customers is our utmost priority. Onapsis is committed to holding our teams and our products to the highest standards. We are committed to both earning and keeping your trust. The Onapsis Trust Center provides verified documentation regarding the security controls, compliance attestations, and software supply chain safeguards protecting the Onapsis Platform.

Platform Architecture and Infrastructure Security
The Onapsis Platform leverages modern infrastructure as code (IaC) capabilities to deliver a cost-effective, easy-to-deploy, easy-to-maintain, independent, and cyber-resilient architecture for securing enterprise applications, whether they’re located on premises, privately hosted, or part of managed cloud deployments (e.g., RISE with SAP).
Data in Transit
Onapsis encrypts all controlled network communication between sensors, management consoles, and APIs using TLS 1.3.
Data at Rest
Onapsis protects customer database records, configuration profiles, and application telemetry using AES-256 encryption.
Tenant Isolation
The Onapsis cloud control plane operates on tier-1 cloud infrastructure, enforcing strict logical database separation to guarantee customer data privacy.
Data Governance and Threat Intelligence Telemetry
Onapsis strictly enforces data privacy principles compliant with global standards like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Robust data governance enables multinational organizations to safely process global threat intelligence while employing strict measures designed to protect personally identifiable information (PII) and corporate identifiers.
Data Control & Ownership
Customers act as Data Controllers and retain full control and ownership of their ERP logs, system configurations, and master business data.
Anonymized Telemetry
Onapsis Research Labs employs robust Technical and Organizational Measures (TOMs) designed to minimize exposure and protect PII before analyzing threat signals from global sensor networks and opt-in telemetry.
Cross-Border Transfers
Onapsis maintains an active EU-U.S. Data Privacy Framework (DPF) self-assessment certification to demonstrate compliance with international privacy laws. Additionally, we incorporate Standard Contractual Clauses (SCCs) directly into our Data Processing Agreements (DPAs) to govern international data transfers.

SAP Endorsed App: Premium Certification
Onapsis is the only cybersecurity and compliance solution in the invitation-only, SAP Endorsed Apps program. This premium certification by SAP themselves independently validates solution security, compatibility, and excellence, giving SAP customers absolute assurance of platform stability. View Directory
Invitation-Only Strategic Partnership
The only cybersecurity and compliance solution in the SAP Endorsed Apps program.
Rigorous Premium Certification
Requires added security, rigorous in-depth testing, and independent codebase audits for platform stability and API compatibility.
Superior Protection vs. Competitors
Other SAP security vendors rely on basic, self-assessed certifications, whereas ALL Onapsis products are premium certified and fully recommended by SAP.

Global Compliance Certifications and Audited Frameworks
Onapsis maintains an active portfolio of third-party compliance certifications and independent security audits. Continuous external validation provides enterprise vendor risk management teams with verifiable proof that Onapsis and Onapsis technology meet the highest global standards for data security, availability, and privacy.
SOC 1 and SOC 2 Type II
Onapsis undergoes annual independent examinations covering Security, Availability, and Confidentiality.
ISO/IEC 27001:2022 (ISMS)
Onapsis has maintained active certification since 2019, validating corporate information security controls across the Onapsis Platform and Onapsis Cloud Platform processes for software development, client implementation, and customer experience. View Certification
ISO 20243:2018 (O-TTPS)
Onapsis proves the structural integrity of the commercial codebase, ensuring our software development lifecycle (SDLC) remains secure from supply-chain tampering across all phases of the product life cycle (design, sourcing, build, fulfillment, distribution, and sustainment). View O-TTPS Register | View Certificate
TISAX Level 3 (AL3)
Onapsis satisfies the stringent security mandates required by global automotive manufacturers handling information with very high protection needs.
Software Supply Chain Security and Secure SDLC
Onapsis enforces strict secure coding standards throughout the engineering lifecycle to prevent technical vulnerabilities from entering commercial software releases. A secure software development lifecycle (SDLC) ensures that the enterprise security tools protecting your applications never introduce new, unintended supply chain vulnerabilities.
Veracode Verified Program
Onapsis has actively participated in the Veracode Verified program since 2020, demonstrating our commitment to rigorous and secure application development standards. View Directory
Internal DevSecOps
Onapsis engineers deploy Onapsis Control within internal development pipelines to scan proprietary code before release.
Static & Dynamic Analysis
Onapsis build systems execute automated static application security testing (SAST) and software composition analysis (SCA) to flag open-source vulnerability risks, including both deterministic and LLM-based capabilities
Vulnerability Disclosure Program (VDP)
Onapsis maintains a formal, structured process for receiving and triaging security reports submitted by independent researchers.
Vendor Risk Resource Center and NDA Requests
Onapsis can provide procurement teams, CISOs, and vendor risk assessors with direct access to formal audit documentation. Streamlining document access directly accelerates the vendor risk management assessment and speeds up software procurement cycles for enterprise buyers.
Full SOC 1 and SOC 2 Type II reports are highly confidential and strictly shared under an active Non-Disclosure Agreement (NDA) or under contracts with existing confidentiality terms in place. Your Onapsis Account Manager or Sales Representative can securely provision these reports to your team directly via Salesforce, Whistic, or as a secured PDF.
Additional Resources: For a full directory of our public compliance materials, please visit the Onapsis Compliance Resources Page.
