SOC2C

Is this your company? Buyers are checking OneRail here. Claim onerail.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
OneRail logo

OneRail

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

OneRail is SOC 2 Type II compliant. OneRail also holds ISO 27001, GDPR, HIPAA, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Leveraging our massive driver network, actionable data and the ability to change delivery outcomes, OneRail gives supply chain professionals the competitive advantage to seamlessly fulfill from store, same-day or warehouse, across all legacy systems. Here, you can find relevant, real-time security control information and documentation. You can access documents like our SOC II attestations and Penetration Tests. Please note that some document access may request you to agree to a Non Disclosure Agreement.

Compliance & infrastructure

Hosting
Azure
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

1

Subprocessors

6
  • M
    Microsoft Azure · Cloud Service Provider
    US
  • G
    GitHub · Version control
    US
  • S
    Slack · Employee Communication
    US
  • D
    Datadog · Analytics and Monitoring
    US
  • S
    Salesforce · Sales
    US
  • S
    Snowflake · Data storage and processing

Compliance leadership

The person who leads OneRail's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. OneRail's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

OneRail Achieves ISO27001:2022Sep 2025

OneRail is proud to announce that we have achieved ISO/IEC 27001:2022 certification, the leading international standard for information security management. This certification demonstrates that OneRail’s Information Security Management System (ISMS) has been independently audited and verified to meet rigorous global standards for managing security, risk, and compliance. Combined with our SOC 2 Type II reports and other controls, ISO/IEC 27001:2022 reinforces our commitment to protecting customer data, ensuring operational resilience, and maintaining trust.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is OneRail SOC 2 compliant?
OneRail is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is OneRail ISO 27001 certified?
According to OneRail's public trust center, OneRail is ISO 27001 certified. On SOC2C this listing is Listed.
Is OneRail GDPR compliant?
According to OneRail's public trust center, OneRail is GDPR compliant. On SOC2C this listing is Listed.
Is OneRail HIPAA compliant?
According to OneRail's public trust center, OneRail is HIPAA compliant. On SOC2C this listing is Listed.
Is OneRail CCPA compliant?
According to OneRail's public trust center, OneRail is CCPA compliant. On SOC2C this listing is Listed.

Answers published by OneRail

Reproduced from OneRail's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Which independent audits and certifications has OneRail completed?
OneRail undergoes annual SOC 2 Type II audits covering all five Trust Service Criteria and achieved ISO/IEC 27001:2022 certification. We also align with HIPAA, GDPR, and other privacy regulations. Audit reports and certifications can be shared under NDA via our Trust Center.
How does OneRail handle vulnerability management and incident response?
We run continuous vulnerability scanning (cloud, endpoints, applications) and track remediation against defined SLAs. We have a documented Incident Response Plan with 24/7 monitoring and escalation. Any event impacting security or privacy triggers immediate triage, investigation, containment, and customer notification as required by law or contract.
What controls are in place to protect production environments and customer data?
Production systems run in segregated environments with enforced RBAC, PIM/JIT access, encryption at rest and in transit, network segmentation, and continuous logging/monitoring. No developer or contractor has standing privileged access; all elevated access is time-bound, logged, and reviewed.
How does OneRail ensure compliance with privacy regulations (GDPR, HIPAA, CCPA)?
We operate as a data processor and only process personal data under customer instruction. Data Subject Requests (DSRs) are handled through defined procedures. PHI/PII is encrypted, access is strictly limited, and retention follows the data minimization principle. We maintain a GDPR Compliance Policy and HIPAA safeguards covering privacy, security, and breach notification.
How are third-party vendors and subcontractors vetted and monitored?
All vendors go through Third-Party Risk Management reviews, including security due diligence, contractual data protection clauses, and ongoing monitoring. Vendors with access to sensitive systems/data must meet our minimum security standards, and we audit compliance regularly.