Security

Security is the foundation
of trusted AI

At onecompliant.ai, security is not treated as a compliance checkbox or isolated technical function. It is integrated into governance, architecture, operations, development, and enterprise decision-making.

Modern organisations are rapidly adopting AI, cloud platforms, automation, and interconnected services. While these technologies create operational advantages, they also introduce new forms of risk:

Sensitive data exposure
Uncontrolled AI interactions
Identity and access misuse
Insecure integrations
Supply chain vulnerabilities
Regulatory non-compliance
AI-driven operational risk
Expanded attack surfaces

OneCompliant™ helps organisations establish structured security controls that support innovation while maintaining operational trust, resilience, and governance.

Security Areas

Key cybersecurity and AI security domains

AI Security & Governance
AI governance frameworks
AI risk assessments
Secure AI deployment strategies
AI usage policies and controls
LLM and agentic AI security
AI data protection and lifecycle governance
Regulatory alignment for AI adoption
Enterprise Cybersecurity
Security strategy and leadership
Cybersecurity governance
Risk management
Security architecture
Security programme maturity
Regulatory and compliance alignment
Executive and board-level advisory
Cloud & Infrastructure Security
Cloud security assessments
Hybrid environment security
Secure architecture design
Identity and access governance
Zero Trust principles
Data protection controls
Security monitoring integration
Security Operations & Resilience
SOC strategy and optimisation
Incident response preparedness
Threat visibility and monitoring
Security automation and orchestration
Vulnerability management guidance
Operational security resilience
Security Philosophy

How we approach security

AI security is a management challenge, not only a technical challenge
Governance must exist before large-scale AI deployment
Security controls should enable business operations, not obstruct them
Visibility and accountability are critical in AI-driven environments
Trust must be continuously maintained through operational discipline

The objective is not simply to deploy AI securely. The objective is to help organisations maintain control, trust, compliance, and resilience as AI becomes integrated into enterprise operations.

Responsible Security Practices

Aligned to international standards

Security recommendations are tailored to organisational risk tolerance, operational requirements, regulatory obligations, and business objectives — aligned to recognised international standards and frameworks.

ISO 27001 ISO 42001 NIST CSF NIST AI RMF GDPR NIS2 DORA EU AI Act
Trust & Procurement

Security posture at a glance

The following statements describe how OneCompliant operates its own services. They are intended to support vendor due diligence and procurement review. Where a control is planned or a specific detail is still being finalised, this is stated honestly rather than overstated.

Legal entity

OneCompliant s.r.o. — an independently owned Slovak technology company incorporated in the Slovak Republic (European Union). Company ID (IČO): 53024231 · Tax ID (DIČ): 2121226635. Registered with the Municipal Court Bratislava III, Commercial Register file Sro/146916/B.

Registered office

Karpatské námestie 7700/10A, 831 06 Bratislava – Rača, Slovak Republic (EU).

Hosting region

Customer and operational data is hosted within the European Union. Specific hosting regions are documented in the applicable data-processing agreement, and data is not stored outside the EU without a lawful transfer mechanism.

Cloud providers

Infrastructure is operated on established enterprise cloud platforms within EU regions. Specific provider and region details are available to prospective customers on request as part of due diligence.

Subprocessors

A current list of subprocessors engaged in service delivery is maintained and provided to customers on request.

Data-processing agreement

A GDPR Article 28-consistent Data Processing Agreement (DPA), including standard contractual clauses where relevant, is available to customers on request.

Data Protection

Encryption, isolation & retention

Encryption in transit

All connections to OneCompliant services and interfaces are protected in transit using industry-standard TLS (version 1.2 or higher). Plaintext protocols are not used for the transmission of customer or operational data.

Encryption at rest

Customer and operational data is encrypted at rest using industry-standard algorithms (such as AES-256) provided by the underlying cloud platform, with encryption keys managed through the platform's managed key service.

Tenant isolation

The platform is designed to logically separate customer environments and data so that one tenant cannot access another tenant's data. Isolation is enforced through access controls and application-level segregation.

Data retention

Customer data is retained for the duration of the service relationship and is deleted or returned following termination in line with contractual and legal requirements. Specific retention periods are set out in the applicable data-processing agreement.

Identity & Access

Access management and administration

Identity & access management

Access to production systems follows least-privilege and role-based access control. Administrative access requires individual named accounts and multi-factor authentication.

Administrator controls

Privileged administrative actions are restricted to authorised personnel, granted on a need-to-know basis, logged, and reviewed. Access is revoked promptly when no longer required.

Logging

Security-relevant events and administrative activity are logged to support monitoring, traceability, and incident investigation. Log retention periods are defined per engagement and available on request.

Secure Operations

Development, vulnerabilities & testing

Secure development lifecycle

Changes follow a controlled development process incorporating peer code review, version control, and separation of development and production environments. Security is considered throughout design and delivery.

Vulnerability management

Systems and dependencies are monitored for known vulnerabilities, and patches are applied on a risk-prioritised basis. Formalising a documented remediation cadence is part of our assurance roadmap.

Penetration testing

Independent penetration testing is part of our assurance roadmap. Where testing has been performed, findings are triaged and remediated on a risk-prioritised basis, and summary results can be made available to prospective customers under NDA.

Incident response

OneCompliant maintains an incident response process covering detection, triage, containment, remediation, and notification. Affected customers are notified without undue delay in line with contractual and GDPR obligations.

Resilience

Backups, continuity & recovery

Backups

Operational data is backed up on a regular schedule, with backups stored within the EU. Backup frequency and retention are defined per engagement and available on request.

Business continuity

Business continuity arrangements to maintain critical operations during disruption are being formalised as part of our assurance roadmap.

Disaster recovery

Disaster recovery procedures are designed to restore service following a major incident, with recovery objectives for critical systems defined per engagement.

Privacy controls

Personal data is processed in accordance with the GDPR, supporting data-subject rights, data minimisation, purpose limitation, and lawful-basis requirements. Full details are set out in our Privacy Policy.

Assurance roadmap

Certifications & independent assurance

OneCompliant does not currently hold formal security or management-system certifications. Our internal control framework is aligned to recognised international standards, and we are progressing toward independent certification. The items below reflect current status using forward-looking language; nothing on this page should be read as a claim that certification has already been achieved.

ISO/IEC 27001 (information security management) — internal alignment in place; formal certification is on our assurance roadmap.
ISO/IEC 42001 (AI management systems) — internal alignment in place; formal certification is on our assurance roadmap.
SOC 2 — under evaluation as a future assurance option.

In the interim, prospective and existing customers can request supporting documentation — including our security overview, DPA, and subprocessor list — to support due diligence.

Disclosure & Communication

If you believe you have identified a security issue related to OneCompliant services, communications, or publicly exposed infrastructure, please contact OneCompliant through official communication channels.

Please do not attempt unauthorised access, disruption, exploitation, or testing of systems without explicit written authorisation.

kevin@onecompliant.ai