Independently verified · Risk rating LOW

Security built in from day one

Your financial data deserves the highest level of protection. OneCap has been independently assessed by an external security firm — all critical findings resolved.

AES-256 encryption at rest

All stored financial data — statements, ledgers, reconciliation histories — is encrypted with AES-256.

TLS 1.3 in transit

Every connection between your systems and OneCap is encrypted end to end. No plaintext, anywhere.

Hosted on AWS

Infrastructure runs on AWS cloud with isolated environments and managed, audited services.

Independent VAPT audits

Vulnerability assessment and penetration testing by an external security firm. All critical findings resolved; overall risk rating LOW.

Role-based access

Granular permissions for makers, checkers and viewers — aligned with finance control structures.

Complete audit trails

Every match, override and resolution is logged with who, when and why — designed for scrutiny.

Questions about our security posture?

We'll walk your security team through the full assessment report.

Talk to us