Start your security review
View & download sensitive information
ControlK

Welcome to the OneHQ Trust Center.

OneHQ provides an all-in-one platform for insurance distribution organizations, including a CRM for sales teams, a DMS for back-office operations, ICM for commissions management, and a robust Agent Portal. Because our platform supports critical business processes and information, protecting your data is central to everything we do.

This Trust Center provides a clear, accessible overview of OneHQ’s security, compliance, and data protection practices. Our security program includes comprehensive policies and controls aligned with the SOC 2 Trust Services Criteria for Security, Availability, Confidentiality, and Processing Integrity.

Key aspects of our security and trust program include:

  • Robust Data Protection: We employ a standardized framework for classifying and safeguarding data based on its sensitivity, legal requirements, and potential risk. This includes defining clear guidelines for handling confidential, restricted, and internal data, ensuring appropriate controls are applied throughout its lifecycle. We also utilize cryptographic controls to protect the confidentiality, integrity, authenticity, and nonrepudiation of information across our systems.
  • Operational Security Practices: Our systems are hosted using Amazon Web Services (AWS) and Microsoft Azure (Azure), and we maintain rigorous oversight of these subservice organizations, including reviewing their attestation reports and monitoring external communications. Physical access to data centers is restricted to authorized individuals and monitored 24/7, with environmental controls in place to protect systems. We also have defined incident response procedures that are reviewed annually.
  • Comprehensive Risk Management: We have a systematic approach to identifying, assessing, and treating information security risks, ensuring that threats and vulnerabilities are addressed and an acceptable level of risk is maintained.
  • Employee Security and Awareness: We recognize that our team members are a critical component of security. Our Members Security Policy defines expectations, controls, and procedures for all team members, contractors, and vendors, ensuring they understand their roles and responsibilities regarding security and privacy.
  • Vendor Compliance: We actively monitor the compliance of our critical vendors and service providers with industry frameworks, regulations, and our own requirements.
  • Cybersecurity Insurance: OneHQ maintains cybersecurity insurance to mitigate the financial impact of potential security incidents.

Explore this Trust Center to learn more about the policies, controls, and practices OneHQ uses to protect your information and maintain the security, availability, and integrity of our services.

  • A-LIGN

Documents

COMPLIANCESOC 2 Type 2

Risk Profile

We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request.

Self-Assessments

We are working on our security compliance. We can provide completed questionnaires upon request.

AI

We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.

ESG

We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.

Security Grades

We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo