Your data, protected by design.
Every Owesome product is built on the same security foundation. This page covers the controls we use to protect your team's data.
Defense in depth, end to end.
Encryption everywhere
TLS 1.2+ in transit and AES-256 at rest, across every product in the suite.
Strong authentication
SSO, SAML, 2FA and session controls keep the right people in and everyone else out.
Least-privilege access
Role-based permissions and strict internal access controls limit blast radius.
Resilient infrastructure
Isolated environments, DDoS protection and continuous monitoring, 24/7.
Backups & recovery
Automated, encrypted backups with tested disaster-recovery procedures.
Audit & transparency
Tamper-evident audit logs and a public status page you can always check.
Certified, tested and transparent.
- SOC 2 Type II controls
- GDPR & CCPA compliant
- Independent penetration testing
- Responsible disclosure program
- Data Processing Agreement on request
- 99.9% uptime SLA (Enterprise)
Security in every product.
Encrypted everywhere
TLS 1.2+ in transit and AES-256 at rest across every product.
SOC 2 & GDPR
SOC 2 Type II controls and GDPR-ready processing, DPA on request.
SSO & SCIM
SAML single sign-on and directory sync for enterprise identity.
99.9% uptime
Resilient infrastructure with an SLA and a public status page.
Audit logs
A tamper-evident record of every sensitive action, exportable.
Human support
Real people, fast response times and dedicated CSMs on Enterprise.
Everything your security team needs.
Report a vulnerability
Found an issue? Our responsible disclosure program is the fastest way to reach our security team.
Report an issueSOC 2 report & DPA
Our SOC 2 Type II report and Data Processing Agreement are available under NDA on request.
Request documentsSub-processors
A current list of the third parties we use to run Owesome, with the data each one handles.
View sub-processorsSystem status
Live uptime for every product, plus a history of any incidents and how we resolved them.
Check statusHave a security question?
Our team is happy to walk through our controls, share documentation and answer your security questionnaire.