1. Security Principles
Our security program is designed around these principles:
Confidentiality
Protect customer information from unauthorized access.
Integrity
Protect systems and information from unauthorized modification.
Availability
Maintain resilient operations and service continuity.
Accountability
Maintain logging and operational traceability.
Privacy by Design
Incorporate privacy considerations into product and operational decisions.
2. Security Program
OneChannelAdmin maintains administrative, technical, and operational safeguards intended to support secure platform operation.
Security programs are designed to support operational alignment with recognized security and privacy frameworks.
Examples may include
- GDPR principles
- CCPA principles
- CPRA principles
- ISO 27001 practices
- SOC 2 controls
- PCI security principles
Unless separately stated, references to frameworks do not represent formal certification.
3. Infrastructure
Primary Cloud Environment
Amazon Web Services (AWS).
Primary Operating Regions
United States.
Additional processing regions may support customer operations where enabled.
Infrastructure architecture may evolve.
4. Data Protection
Encryption at Rest
- storage encryption
- encrypted backups
- encrypted databases
Stored information may be protected using encryption technologies.
Encryption in Transit
- HTTPS
- TLS
- secure APIs
- encrypted communication
Customer environments are logically separated. Operational boundaries are maintained to reduce unintended access.
5. Access Management
Authentication
- MFA
- SSO
- Google login
- Microsoft login
Authorization
- RBAC
- role permissions
- user scopes
- approval controls
Session Controls
- session expiration
- credential rotation
- access restrictions
6. Application Security
Secure Development
- code review
- security testing
- controlled deployments
- change management
Vulnerability Management
- patching
- dependency updates
- remediation tracking
Periodic penetration testing may occur. Findings may be prioritized according to operational risk.
7. Monitoring and Detection
Security monitoring may include:
- infrastructure monitoring
- application monitoring
- anomaly detection
- audit logs
- operational alerts
- event investigation
Monitoring operates continuously where supported.
8. Audit Logging
Logging capabilities may include:
- login activity
- permission changes
- inventory changes
- workflow execution
- API activity
- system events
Logs are retained according to applicable retention policies.
9. Backup and Resilience
Operational protections may include:
- scheduled backups
- recovery procedures
- operational redundancy
- restoration testing
Backups are intended for operational recovery.
Backups are not archival storage. Retention periods may vary.
10. Incident Response
Security incidents may follow a structured process:
Investigate
Validate and classify.
Recover
Restore operations.
Notifications may occur where required.
11. Customer Data Controls
Customers may manage supported controls including:
- user management
- role permissions
- exports
- deletion requests
- integrations
- API access
Customer remains responsible for:
- access governance
- user administration
- endpoint security
12. Privacy Controls
Customers may request where supported:
- export
- correction
- deletion
- access
Privacy obligations are further described in the Privacy Policy.
13. AI Security
AI features may process:
- prompts
- uploaded files
- generated outputs
AI controls may include:
- access restrictions
- logging
- operational monitoring
- workflow permissions
Customer remains responsible for reviewing AI outputs.
AI usage does not automatically authorize access across ecosystem services.
14. Ecosystem Security
Optional ecosystem services include:
- OneDirectBuy
- OneFulfillCenter
Customers are not required to use affiliated services.
Customer operational information is not intentionally shared across ecosystem services unless enabled.
15. Third-Party Services
OneChannelAdmin may rely on third-party providers.
Examples may include
- infrastructure
- email
- analytics
- AI services
- payment services
- monitoring
Provider details may appear in Subprocessor documentation.
16. Availability
OneChannelAdmin targets operational service availability objectives.
Availability commitments are governed by the Service Level Agreement.
17. Compliance Position
Security programs are designed to support alignment with recognized frameworks.
Current status may vary by service.
Compliance claims should not be interpreted as certification unless explicitly stated.
18. Responsible Disclosure
Reports should include:
- description
- impact
- reproduction information
Customers should avoid disruption while testing.
19. Changes
Security practices may evolve.
Updated versions become effective when published.
OneChannelAdmin LLC
8 W Darlington Ave
Kissimmee, FL 34746
USA