SOC
Here is what our SOC 2 Type II audit supports on your side of the review.
Data protection
Independent verification that OneHQ handles applicant and policyholder data under audited security and confidentiality controls.
Regulatory alignment
Supports the due-diligence documentation your compliance team needs for state data security requirements and internal vendor risk reviews.
Faster vendor review
A current SOC 2 report answers most procurement security questionnaires up front, shortening your own review cycle.

How we protect your data
Encryption
We encrypt data in transit and at rest using industry-standard protocols.
Access control
We use role-based access, single sign-on and multi-factor authentication.
Infrastructure
We host on cloud infrastructure that carries its own independent compliance certifications.
Incident response
We maintain documented incident response and disaster recovery plans and test them regularly.