Trust & compliance
Customer trust, information security and data privacy are at the heart of everything we do at OneIQ.
ISO/IEC 27001 certified, GDPR compliant, annual penetration testing and surveillance audits.
Security is an integral part of our software development - agentless, encrypted, digitally signed.
Hosted on Microsoft Azure Canada Central with extensive security capabilities and SSL everywhere.
Security screening, annual training, SSO with 2FA, and a dedicated Information Security Officer.
OneIQ is ISO/IEC 27001 certified, complies with GDPR, conducts penetration testing and surveillance audits.
OneIQ maintains ISO/IEC 27001 Information Security Management certification through the British Standards Institution (BSI).
BSI Certificate No. IS 714719OneIQ is committed to the General Data Protection Regulation (GDPR) (EU) 2016/679 and handles personal data with the highest standards of care.
OneIQ conducts application and infrastructure penetration testing annually through an independent third-party security firm.
Each year OneIQ undergoes ISO/IEC 27001 surveillance audits with BSI to ensure continuous improvements to our information security management system (ISMS).
Security is an integral part of our application software and our product development.
OneIQ does not deploy agents during data collection, avoiding any increase in the attack surface on target systems.
Passwords entered into the OneIQ Pulse data collector are encrypted using AES-256 and are never displayed in plaintext or transmitted externally.
OneIQ encrypts inventory and performance data at the point of collection, in-transit and at-rest.
The OneIQ Pulse data collector is digitally signed to prevent tampering with embedded scripts and software assemblies.
OneIQ performs web application and container image scanning to identify and mitigate security vulnerabilities on an ongoing basis.
OneIQ uses cloud infrastructure and suppliers with a strong focus on privacy and security.
OneIQ is hosted in the Canada Central (Toronto) region on Microsoft Azure, which provides extensive security capabilities including Azure Firewall and secure cloud storage with encryption-at-rest.
All inter-service communication and data transfers are performed over SSL. Zero-trust networking is enforced throughout, so a single compromised service can never silently reach the rest of your estate.
OneIQ has a rigorous onboarding process for new suppliers and conducts annual reviews of existing suppliers to ensure they maintain rigorous privacy and security policies.
OneIQ performs extensive logging to identify and mitigate security risks and vulnerabilities across all platform components.
Security is at the heart of how we run our business.
OneIQ has a dedicated Information Security Officer responsible for ISO/IEC 27001 compliance, continuous improvement to security policies and procedures, and incident management.
OneIQ has rigorous information security incident management procedures for mitigating security incidents and communicating security events to affected parties.
New staff must undergo criminal record and employment verification checks before joining OneIQ. All contracts include a confidentiality agreement.
All staff complete security training when they join OneIQ and at least once annually for refresh training.
All OneIQ systems have rigorous access controls and require single sign-on (SSO) with two-factor authentication (2FA).
All staff endpoints have BitLocker encryption and security scanning software. Staff must use single sign-on and follow clear-screen policies.
Partner program
Pick an environment and we’ll show you a live governed Agent Zone on it in fifteen minutes.
Become a partner