Built on Enterprise Grade Security Standards

Our Highest Priority is
Your Cloud's Security.

OnDuty Platform is designed from the ground up by kernel-level security engineering experts. We leverage eBPF runtime telemetry to secure our customer environments while dogfooding our own technology.

World Class Security Features

We follow secure-by-default design principles and execute continuous preventive security controls across our platform.

SOC 2 Readiness Program

We are building our operational controls toward a SOC 2 Type II audit (see our Trust Center for the current roadmap). We are not yet certified, and we design our infrastructure, codebase, and workflows against those control standards today.

Zero-Touch Production

All environment deployments follow a strict zero-touch policy. Access is shielded behind private networks with absolutely no open public access.

Data Encrypted at Rest & Transit

Stored data is encrypted with AES-256 (Server-Side Encryption) via KMS. All transit data is strictly encrypted using TLS 1.3 with secure cipher suites.

Ephemeral Secret Storage

Cloud credentials and temporary access credentials used by our telemetry agents are stored in Google Cloud Secret Manager and purged within 24 hours.

Identity & SSO Governance

We enforce passwordless authentication, Single Sign-On (SSO), and Multi-Factor Authentication (MFA) via trusted enterprise identity providers.

Enterprise Cloud Hosting

Hosted entirely on premium Google Cloud Platform (GCP) and AWS regions using isolated VPCs, managed compute resources, and secure boundaries.

Responsible Disclosure

Reporting Vulnerabilities

If you believe you have discovered a security vulnerability in any OnDuty owned property or product, please report it in a responsible manner. Active security testing against our live customer services is strictly prohibited.

GPG Key Encryption

We encourage encrypting sensitive vulnerability reports.

Download OpenPGP public key
Fingerprint: 7B96 65E7 9CAF 83FF 089E 988A 4274 9B7F 74BC 40E0

Reporting Process

1

Scope Verification

Confirm that the vulnerability is within scope (refer to the out-of-scope list below) and verified with manual proof of exploitability.

2

GPG Encrypted Email

Send your findings to security@onduty.ai. We encourage encrypting your message using our public GPG key.

3

Triage & Remediation

Our engineering and security teams will validate the report and respond with a remediation timeline within 3 to 4 business days.

Security & Compliance FAQ

Common questions regarding our data privacy, infrastructure resilience, and kernel telemetry isolation.

Have Questions About Our Security Architecture?

If your compliance or infosec team needs our current security documentation or architecture overviews, contact our trust center. SOC 2 audit reports will be available once our audit is complete.

security@onduty.ai