Modern organisations are rapidly adopting AI, cloud platforms, automation, and interconnected services. While these technologies create operational advantages, they also introduce new forms of risk:
OneCompliant™ helps organisations establish structured security controls that support innovation while maintaining operational trust, resilience, and governance.
Security AreasKey cybersecurity and AI security domains
How we approach security
The objective is not simply to deploy AI securely. The objective is to help organisations maintain control, trust, compliance, and resilience as AI becomes integrated into enterprise operations.
Responsible Security PracticesAligned to international standards
Security recommendations are tailored to organisational risk tolerance, operational requirements, regulatory obligations, and business objectives — aligned to recognised international standards and frameworks.
Security posture at a glance
The following statements describe how OneCompliant operates its own services. They are intended to support vendor due diligence and procurement review. Where a control is planned or a specific detail is still being finalised, this is stated honestly rather than overstated.
OneCompliant s.r.o. — an independently owned Slovak technology company incorporated in the Slovak Republic (European Union). Company ID (IČO): 53024231 · Tax ID (DIČ): 2121226635. Registered with the Municipal Court Bratislava III, Commercial Register file Sro/146916/B.
Karpatské námestie 7700/10A, 831 06 Bratislava – Rača, Slovak Republic (EU).
Customer and operational data is hosted within the European Union. Specific hosting regions are documented in the applicable data-processing agreement, and data is not stored outside the EU without a lawful transfer mechanism.
Infrastructure is operated on established enterprise cloud platforms within EU regions. Specific provider and region details are available to prospective customers on request as part of due diligence.
A current list of subprocessors engaged in service delivery is maintained and provided to customers on request.
A GDPR Article 28-consistent Data Processing Agreement (DPA), including standard contractual clauses where relevant, is available to customers on request.
Encryption, isolation & retention
All connections to OneCompliant services and interfaces are protected in transit using industry-standard TLS (version 1.2 or higher). Plaintext protocols are not used for the transmission of customer or operational data.
Customer and operational data is encrypted at rest using industry-standard algorithms (such as AES-256) provided by the underlying cloud platform, with encryption keys managed through the platform's managed key service.
The platform is designed to logically separate customer environments and data so that one tenant cannot access another tenant's data. Isolation is enforced through access controls and application-level segregation.
Customer data is retained for the duration of the service relationship and is deleted or returned following termination in line with contractual and legal requirements. Specific retention periods are set out in the applicable data-processing agreement.
Access management and administration
Access to production systems follows least-privilege and role-based access control. Administrative access requires individual named accounts and multi-factor authentication.
Privileged administrative actions are restricted to authorised personnel, granted on a need-to-know basis, logged, and reviewed. Access is revoked promptly when no longer required.
Security-relevant events and administrative activity are logged to support monitoring, traceability, and incident investigation. Log retention periods are defined per engagement and available on request.
Development, vulnerabilities & testing
Changes follow a controlled development process incorporating peer code review, version control, and separation of development and production environments. Security is considered throughout design and delivery.
Systems and dependencies are monitored for known vulnerabilities, and patches are applied on a risk-prioritised basis. Formalising a documented remediation cadence is part of our assurance roadmap.
Independent penetration testing is part of our assurance roadmap. Where testing has been performed, findings are triaged and remediated on a risk-prioritised basis, and summary results can be made available to prospective customers under NDA.
OneCompliant maintains an incident response process covering detection, triage, containment, remediation, and notification. Affected customers are notified without undue delay in line with contractual and GDPR obligations.
Backups, continuity & recovery
Operational data is backed up on a regular schedule, with backups stored within the EU. Backup frequency and retention are defined per engagement and available on request.
Business continuity arrangements to maintain critical operations during disruption are being formalised as part of our assurance roadmap.
Disaster recovery procedures are designed to restore service following a major incident, with recovery objectives for critical systems defined per engagement.
Personal data is processed in accordance with the GDPR, supporting data-subject rights, data minimisation, purpose limitation, and lawful-basis requirements. Full details are set out in our Privacy Policy.
Certifications & independent assurance
OneCompliant does not currently hold formal security or management-system certifications. Our internal control framework is aligned to recognised international standards, and we are progressing toward independent certification. The items below reflect current status using forward-looking language; nothing on this page should be read as a claim that certification has already been achieved.
In the interim, prospective and existing customers can request supporting documentation — including our security overview, DPA, and subprocessor list — to support due diligence.
Disclosure & CommunicationIf you believe you have identified a security issue related to OneCompliant services, communications, or publicly exposed infrastructure, please contact OneCompliant through official communication channels.
Please do not attempt unauthorised access, disruption, exploitation, or testing of systems without explicit written authorisation.