OnDuty Platform is designed from the ground up by kernel-level security engineering experts. We leverage eBPF runtime telemetry to secure our customer environments while dogfooding our own technology.
We follow secure-by-default design principles and execute continuous preventive security controls across our platform.
We are building our operational controls toward a SOC 2 Type II audit (see our Trust Center for the current roadmap). We are not yet certified, and we design our infrastructure, codebase, and workflows against those control standards today.
All environment deployments follow a strict zero-touch policy. Access is shielded behind private networks with absolutely no open public access.
Stored data is encrypted with AES-256 (Server-Side Encryption) via KMS. All transit data is strictly encrypted using TLS 1.3 with secure cipher suites.
Cloud credentials and temporary access credentials used by our telemetry agents are stored in Google Cloud Secret Manager and purged within 24 hours.
We enforce passwordless authentication, Single Sign-On (SSO), and Multi-Factor Authentication (MFA) via trusted enterprise identity providers.
Hosted entirely on premium Google Cloud Platform (GCP) and AWS regions using isolated VPCs, managed compute resources, and secure boundaries.
If you believe you have discovered a security vulnerability in any OnDuty owned property or product, please report it in a responsible manner. Active security testing against our live customer services is strictly prohibited.
We encourage encrypting sensitive vulnerability reports.
Download OpenPGP public keyConfirm that the vulnerability is within scope (refer to the out-of-scope list below) and verified with manual proof of exploitability.
Send your findings to security@onduty.ai. We encourage encrypting your message using our public GPG key.
Our engineering and security teams will validate the report and respond with a remediation timeline within 3 to 4 business days.
Common questions regarding our data privacy, infrastructure resilience, and kernel telemetry isolation.
If your compliance or infosec team needs our current security documentation or architecture overviews, contact our trust center. SOC 2 audit reports will be available once our audit is complete.