Role-based access
Each person uses only the functions and information that match their responsibility.
Security and privacy
Onzane builds identity, permissions, encryption, traceability and retention rules into the platform to protect each community’s information and operations.
Layered security
People, data, actions and infrastructure need different controls. Onzane combines them to reduce unnecessary access, preserve evidence and maintain community continuity.
Each person uses only the functions and information that match their responsibility.
Relevant actions are linked to a user, a time and a community context.
Information no longer travels through scattered channels and is managed in a controlled environment.
The community retains its operational knowledge when managers, employees or suppliers change.
No system can promise zero risk. The goal is to prevent, limit impact, detect what matters and make recovery easier.
Identity and access
Onzane lets organisations build access profiles around responsibilities, restrict sensitive functions and remove permissions when they are no longer needed.
Multi-factor authentication adds a second verification step to access that needs greater protection.
Permissions can be grouped into profiles and assigned to managers, boards, employees and other authorised users.
A user does not need global access to complete one task; permissions can be scoped and revoked.
Protection and data lifecycle
Information is protected in transit and at rest. Particularly sensitive data receives additional encryption, and retention follows the purpose, applicable obligations and privacy policy.
Only the data needed to provide each function is requested and processed.
Communications use encrypted connections and particularly sensitive information is also encrypted at rest.
Retention periods follow the processing purpose, contracted service and applicable obligations.
Data subject to expiry is automatically deleted under retention rules and the privacy policy.
Not all information needs the same treatment. Onzane applies controls proportionate to the data type, its sensitivity and associated risk.
Secure development and operations
Security does not end when a release goes live. Onzane development combines maintained components, change review, testing and environment separation to reduce risk across the software lifecycle.
Code and configuration evolve through reviewable processes, with traceability over what changes.
Automated validation helps detect functional and security regressions before changes are deployed.
Frameworks, libraries and services are maintained and updated as their releases and fixes evolve.
External connections use scoped, revocable credentials instead of shared general access.
Continuity and recovery
Continuity combines technical and operational procedures. The aim is to preserve necessary information, restore service after an incident and prevent knowledge from depending on one person or supplier.
Backup mechanisms and recovery procedures protect against loss and operational incidents.
Observability and technical logs help identify anomalies, understand their scope and take action.
Community information stays organised and can be exported, reducing dependence on a particular manager.
Data protection
Onzane integrates technical and organisational measures aimed at compliance with the General Data Protection Regulation. Each party’s specific responsibility depends on the service and processing involved.
Frequently asked questions
The scope of each measure depends on the data, profile and function being used.
Connections to the platform are encrypted. Particularly sensitive information is also encrypted at rest. Controls are applied in proportion to the data type and risk.
Only authorised users according to their role and permissions. The community can define custom profiles to limit specific modules, data and actions.
Yes. Certain data subject to expiry is deleted through automated rules. Periods depend on purpose, contract, applicable obligations and the privacy policy.
Yes. Multi-factor authentication can strengthen access with a second verification step, especially for profiles with administration permissions.
Information remains linked to the community and organised within the platform. This reduces loss of context and supports continuity and data export.
Onzane applies privacy by design, minimisation, limited retention and technical and organisational measures aimed at GDPR compliance. Specific responsibilities are defined according to the service and each party’s role in processing.
Integrations use specific, scoped and revocable credentials. Before a connection is enabled, the information and operations it actually needs are defined.
Security from the start
Tell us which information, profiles and integrations you need to protect and we will assess the right configuration with you.