Skip to main content
Cybersecurity & Compliance

SOC

Here is what our SOC 2 Type II audit supports on your side of the review.

  • Data protection

    Independent verification that OneHQ handles applicant and policyholder data under audited security and confidentiality controls.

  • Regulatory alignment

    Supports the due-diligence documentation your compliance team needs for state data security requirements and internal vendor risk reviews.

  • Faster vendor review

    A current SOC 2 report answers most procurement security questionnaires up front, shortening your own review cycle.

AICPA SOC for Service Organizations badge

How we protect your data

Encryption

We encrypt data in transit and at rest using industry-standard protocols.

Access control

We use role-based access, single sign-on and multi-factor authentication.

Infrastructure

We host on cloud infrastructure that carries its own independent compliance certifications.

Incident response

We maintain documented incident response and disaster recovery plans and test them regularly.

Questions? Answers.

Who audited OneHQ?
How often are you audited?
What's the difference between SOC 2 Type I and Type II?
Can I see your SOC 2 report?
Does SOC 2 Type II mean my agency is automatically compliant too?
What happens if there is an incident?
How do I report a security issue or vulnerability?
What data do you collect?
Reduce busy work and help more clients.
Our technology is the key to unlocking more sales and providing professional service.