AES-256 encryption at rest
All stored financial data — statements, ledgers, reconciliation histories — is encrypted with AES-256.
TLS 1.3 in transit
Every connection between your systems and OneCap is encrypted end to end. No plaintext, anywhere.
Hosted on AWS
Infrastructure runs on AWS cloud with isolated environments and managed, audited services.
Independent VAPT audits
Vulnerability assessment and penetration testing by an external security firm. All critical findings resolved; overall risk rating LOW.
Role-based access
Granular permissions for makers, checkers and viewers — aligned with finance control structures.
Complete audit trails
Every match, override and resolution is logged with who, when and why — designed for scrutiny.
Questions about our security posture?
We'll walk your security team through the full assessment report.