Security and privacy

Secure by design.
Control at every layer.

Onzane builds identity, permissions, encryption, traceability and retention rules into the platform to protect each community’s information and operations.

Layered security

Protection does not depend
on a single control.

People, data, actions and infrastructure need different controls. Onzane combines them to reduce unnecessary access, preserve evidence and maintain community continuity.

01

Role-based access

Each person uses only the functions and information that match their responsibility.

02

Traceability

Relevant actions are linked to a user, a time and a community context.

03

Centralised information

Information no longer travels through scattered channels and is managed in a controlled environment.

04

Continuity

The community retains its operational knowledge when managers, employees or suppliers change.

No system can promise zero risk. The goal is to prevent, limit impact, detect what matters and make recovery easier.

Identity and access

Everyone signs in
with the access they need.

Onzane lets organisations build access profiles around responsibilities, restrict sensitive functions and remove permissions when they are no longer needed.

Stronger authentication

Multi-factor authentication adds a second verification step to access that needs greater protection.

Roles and custom profiles

Permissions can be grouped into profiles and assigned to managers, boards, employees and other authorised users.

Least privilege

A user does not need global access to complete one task; permissions can be scoped and revoked.

Custom profileOperations managementAssigned to authorised users
AnnouncementsAllowed
DocumentsAllowed
AccountingRestricted
Access controlAllowed

Permission changes and relevant actions can be recorded for review.

Protection and data lifecycle

Protection also means
not keeping too much.

Information is protected in transit and at rest. Particularly sensitive data receives additional encryption, and retention follows the purpose, applicable obligations and privacy policy.

  1. 01

    Minimise

    Only the data needed to provide each function is requested and processed.

  2. 02

    Encrypt

    Communications use encrypted connections and particularly sensitive information is also encrypted at rest.

  3. 03

    Retain

    Retention periods follow the processing purpose, contracted service and applicable obligations.

  4. 04

    Delete

    Data subject to expiry is automatically deleted under retention rules and the privacy policy.

Encryption with a realistic scope.

Not all information needs the same treatment. Onzane applies controls proportionate to the data type, its sensitivity and associated risk.

Secure development and operations

Maintained technology.
Controls throughout change.

Security does not end when a release goes live. Onzane development combines maintained components, change review, testing and environment separation to reduce risk across the software lifecycle.

01

Controlled changes

Code and configuration evolve through reviewable processes, with traceability over what changes.

02

Automated testing

Automated validation helps detect functional and security regressions before changes are deployed.

03

Continuous updates

Frameworks, libraries and services are maintained and updated as their releases and fixes evolve.

04

Protected integrations

External connections use scoped, revocable credentials instead of shared general access.

Continuity and recovery

Ready to continue
and to recover.

Continuity combines technical and operational procedures. The aim is to preserve necessary information, restore service after an incident and prevent knowledge from depending on one person or supplier.

01

Backups and recovery

Backup mechanisms and recovery procedures protect against loss and operational incidents.

02

Logging and diagnosis

Observability and technical logs help identify anomalies, understand their scope and take action.

03

Data with continuity

Community information stays organised and can be exported, reducing dependence on a particular manager.

Data protection

Privacy by design
and aligned with the GDPR.

Onzane integrates technical and organisational measures aimed at compliance with the General Data Protection Regulation. Each party’s specific responsibility depends on the service and processing involved.

  • Data protection by design and by default.
  • Data minimisation, purpose limitation and limited retention.
  • Information about processing and the exercise of rights.
  • Defined contractual relationships and responsibilities for each service.
Read the privacy policy

Frequently asked questions

Security and privacy, clearly explained.

The scope of each measure depends on the data, profile and function being used.

01Is all Onzane information encrypted?

Connections to the platform are encrypted. Particularly sensitive information is also encrypted at rest. Controls are applied in proportion to the data type and risk.

02Who can see a community’s information?

Only authorised users according to their role and permissions. The community can define custom profiles to limit specific modules, data and actions.

03Does Onzane automatically delete data?

Yes. Certain data subject to expiry is deleted through automated rules. Periods depend on purpose, contract, applicable obligations and the privacy policy.

04Does Onzane support multi-factor authentication?

Yes. Multi-factor authentication can strengthen access with a second verification step, especially for profiles with administration permissions.

05What happens when the manager or service company changes?

Information remains linked to the community and organised within the platform. This reduces loss of context and supports continuity and data export.

06Does Onzane comply with the GDPR?

Onzane applies privacy by design, minimisation, limited retention and technical and organisational measures aimed at GDPR compliance. Specific responsibilities are defined according to the service and each party’s role in processing.

07How are integrations with other systems protected?

Integrations use specific, scoped and revocable credentials. Before a connection is enabled, the information and operations it actually needs are defined.

Security from the start

Let us review your organisation’s requirements.

Tell us which information, profiles and integrations you need to protect and we will assess the right configuration with you.