Why Onapsis

The Onapsis Trust Center: Enterprise Security and Compliance

The privacy and security of our customers is our utmost priority. Onapsis is committed to holding our teams and our products to the highest standards. We are committed to both earning and keeping your trust. The Onapsis Trust Center provides verified documentation regarding the security controls, compliance attestations, and software supply chain safeguards protecting the Onapsis Platform.

Developer working at multiple computer monitors

Platform Architecture and Infrastructure Security

The Onapsis Platform leverages modern infrastructure as code (IaC) capabilities to deliver a cost-effective, easy-to-deploy, easy-to-maintain, independent, and cyber-resilient architecture for securing enterprise applications, whether they’re located on premises, privately hosted, or part of managed cloud deployments (e.g., RISE with SAP).

Data in Transit

Onapsis encrypts all controlled network communication between sensors, management consoles, and APIs using TLS 1.3.

Data at Rest

Onapsis protects customer database records, configuration profiles, and application telemetry using AES-256 encryption.

Tenant Isolation

The Onapsis cloud control plane operates on tier-1 cloud infrastructure, enforcing strict logical database separation to guarantee customer data privacy.

Data Governance and Threat Intelligence Telemetry

Onapsis strictly enforces data privacy principles compliant with global standards like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Robust data governance enables multinational organizations to safely process global threat intelligence while employing strict measures designed to protect personally identifiable information (PII) and corporate identifiers.

Data Control & Ownership

Customers act as Data Controllers and retain full control and ownership of their ERP logs, system configurations, and master business data.

Anonymized Telemetry

Onapsis Research Labs employs robust Technical and Organizational Measures (TOMs) designed to minimize exposure and protect PII before analyzing threat signals from global sensor networks and opt-in telemetry.

Cross-Border Transfers

Onapsis maintains an active EU-U.S. Data Privacy Framework (DPF) self-assessment certification to demonstrate compliance with international privacy laws. Additionally, we incorporate Standard Contractual Clauses (SCCs) directly into our Data Processing Agreements (DPAs) to govern international data transfers.

SAP Endorsed App: Premium Certification

Invitation-Only Strategic Partnership

The only cybersecurity and compliance solution in the SAP Endorsed Apps program.

Rigorous Premium Certification

Requires added security, rigorous in-depth testing, and independent codebase audits for platform stability and API compatibility.

Superior Protection vs. Competitors

Other SAP security vendors rely on basic, self-assessed certifications, whereas ALL Onapsis products are premium certified and fully recommended by SAP.

SAP Endorsed App, Premium Certified

Global Compliance Certifications and Audited Frameworks

Onapsis maintains an active portfolio of third-party compliance certifications and independent security audits. Continuous external validation provides enterprise vendor risk management teams with verifiable proof that Onapsis and Onapsis technology meet the highest global standards for data security, availability, and privacy.

SOC 1 and SOC 2 Type II

Onapsis undergoes annual independent examinations covering Security, Availability, and Confidentiality.

ISO/IEC 27001:2022 (ISMS)

Onapsis has maintained active certification since 2019, validating corporate information security controls across the Onapsis Platform and Onapsis Cloud Platform processes for software development, client implementation, and customer experience. View Certification

ISO 20243:2018 (O-TTPS)

Onapsis proves the structural integrity of the commercial codebase, ensuring our software development lifecycle (SDLC) remains secure from supply-chain tampering across all phases of the product life cycle (design, sourcing, build, fulfillment, distribution, and sustainment). View O-TTPS Register | View Certificate

TISAX Level 3 (AL3)

Onapsis satisfies the stringent security mandates required by global automotive manufacturers handling information with very high protection needs.

Software Supply Chain Security and Secure SDLC

Onapsis enforces strict secure coding standards throughout the engineering lifecycle to prevent technical vulnerabilities from entering commercial software releases. A secure software development lifecycle (SDLC) ensures that the enterprise security tools protecting your applications never introduce new, unintended supply chain vulnerabilities.

Veracode Verified Program

Onapsis has actively participated in the Veracode Verified program since 2020, demonstrating our commitment to rigorous and secure application development standards. View Directory

Internal DevSecOps

Onapsis engineers deploy Onapsis Control within internal development pipelines to scan proprietary code before release.

Static & Dynamic Analysis

Onapsis build systems execute automated static application security testing (SAST) and software composition analysis (SCA) to flag open-source vulnerability risks, including both deterministic and LLM-based capabilities

Vulnerability Disclosure Program (VDP)

Onapsis maintains a formal, structured process for receiving and triaging security reports submitted by independent researchers.

Vendor Risk Resource Center and NDA Requests

Onapsis can provide procurement teams, CISOs, and vendor risk assessors with direct access to formal audit documentation. Streamlining document access directly accelerates the vendor risk management assessment and speeds up software procurement cycles for enterprise buyers.

Full SOC 1 and SOC 2 Type II reports are highly confidential and strictly shared under an active Non-Disclosure Agreement (NDA) or under contracts with existing confidentiality terms in place. Your Onapsis Account Manager or Sales Representative can securely provision these reports to your team directly via Salesforce, Whistic, or as a secured PDF.

Additional Resources: For a full directory of our public compliance materials, please visit the Onapsis Compliance Resources Page.