SOC2C

Is this your company? Buyers are checking Onetrace Ltd here. Claim onetrace.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Onetrace Ltd logo

Onetrace Ltd

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Onetrace Ltd is SOC 2 compliant. Onetrace Ltd also holds ISO 27001, and GDPR.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

A powerful cloud-based application that has been developed from the ground up, Onetrace supports subcontractors across the construction industry, by providing one system to capture, monitor, review and report on all work being conducted in real time.

Compliance & infrastructure

Hosting
AWSGCP

Subprocessors

23
  • A
    Amazon Web Services · Cloud provider
    United Kingdom
  • M
    MongoDB · Data storage and processing
    United States
  • S
    Sentry · Cloud monitoring
    United States
  • S
    Stripe · Finance and payments
    United Kingdom
  • A
    Aircall · Customer support
    United Kingdom
  • A
    Amazon Web Services (Intercom) · Cloud infrastructure and hosting
    United States
  • A
    Anthropic · Large Language Model (LLM)
    United States
  • C
    Calendly · Collaboration
    United States
  • C
    Clay · Sales & Marketing
    United States
  • C
    Clerk · Identity provider
    United States
  • G
    Google LLC · Cloud
    United States
  • G
    Gong · Sales
    United States
Show all 23 subprocessors
  • H
    Hotjar · Analytics
    Ireland
  • I
    Intercom · Customer support
    United States
  • J
    Juro · Contract lifecycle management
    United Kingdom
  • L
    Loom · Screen recording
    United States
  • M
    MailerLite · Email marketing
    Germany, Netherlands
  • M
    MailerSend · Transactional email service
    Germany, Belgium
  • N
    N8N · Workflow automation
    Germany
  • O
    OpenAI · Engineering
    United States
  • P
    Planhat · Customer success
    United Kingdom
  • P
    PowerSync · Backup Sync
    Europe
  • S
    Slack · Collaboration
    United States

Compliance leadership

The person who leads Onetrace Ltd's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Onetrace Ltd's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Onetrace Ltd SOC 2 compliant?
Onetrace Ltd is SOC 2 compliant. On SOC2C this listing is Listed.
Is Onetrace Ltd ISO 27001 certified?
According to Onetrace Ltd's public trust center, Onetrace Ltd is ISO 27001 certified. On SOC2C this listing is Listed.
Is Onetrace Ltd GDPR compliant?
According to Onetrace Ltd's public trust center, Onetrace Ltd is GDPR compliant. On SOC2C this listing is Listed.
Can I use Onetrace Ltd's SOC 2 for a vendor risk assessment?
Yes. Onetrace Ltd's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Onetrace Ltd penetration tested?
Onetrace Ltd hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Onetrace Ltd

Reproduced from Onetrace Ltd's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Where will the system's data be hosted?
Core platform data (projects, jobs, materials etc.) is hosted in AWS UK (London, eu-west-2). Support chat data processed via Intercom's AI agent is stored in the US (AWS US-East, Northern Virginia), covered by Intercom's DPA and SCCs.
Will all data be hosted and processed within the UK or EU?
Not entirely. Core operational data is UK-hosted (AWS London). Support chat data via Intercom is processed in the US, with SCCs in place to cover that transfer.
Which data centres are backups stored in?
Both primary data and backups are hosted in AWS London (eu-west-2).
If the system went down or was hacked, where are documents stored and how could they be accessed?
Data and documents are stored in cloud infrastructure with automated backups and versioning. In the event of a compromise, systems would be isolated, access secured, and the most recent clean backup restored. Infrastructure access is controlled via RBAC and MFA.
Is all data encrypted at rest?
Yes, all data is encrypted at rest using AES-256, including all MongoDB Atlas backups.

Business & Industrial peers that completed SOC 2