Oninit® Legal Center — Security Overview
Security Principles
- Least privilege access
- Defense in depth
- Encryption where appropriate
- Monitoring and logging
- Backup and recovery procedures
- Change management controls
Customer Data
Customer data is not sold.
Incident Response
Security incidents are investigated and addressed according to internal procedures. Oninit will notify affected customers of confirmed security incidents involving their Customer Content without undue delay, and in any event consistent with applicable legal requirements. Notification will include the information reasonably available at the time, with updates as the investigation progresses.
Business Continuity
Oninit maintains backup and recovery procedures designed to support continuity of the Services. Specifics, including recovery objectives, are reviewed periodically and made available to customers under non-disclosure on request.
Vulnerability Reporting
Suspected vulnerabilities may be reported in good faith to security@oninit.com. Oninit appreciates coordinated disclosure and will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give Oninit a reasonable opportunity to remediate before public disclosure.