SOC2C

Onit security & compliance

An overview of Onit's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II, ISO 27001, HIPAA, GDPR
Penetration testNot listed
Subprocessors29 listed
HostingAWS
Trust centerView

Security questions about Onit

Is Onit secure?
Security isn't a single yes/no, but Onit is SOC 2 Type II compliant and holds SOC 2 Type II, ISO 27001, HIPAA, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Onit have a bug bounty or vulnerability disclosure program?
Onit hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@onit.com or via a /security page.
Who are Onit's subprocessors?
Onit lists 29 subprocessors on its trust center, including Affinda, Amazon Web Services (AWS), Asana, AXDRAFT, LLC, BusyLamp GmbH. Buyers use this for fourth-party risk review.
Where does Onit host or store data?
Onit hosts on AWS. Data residency details are on its trust center.
Where is Onit's trust center or security page?
Onit's trust center is at https://trust.onit.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Onit's full SOC 2 profile →