Security you can trust

Security has moved beyond IT. It’s now a business essential. Customers expect it. Regulators demand it. And getting it wrong has real consequences. That’s why security is built into the foundation of Onguard. So your data, processes and reputation stay protected, today and tomorrow.

image/svg+xml

Compliance and independent audits

Onguard’s security and compliance controls are independently audited against internationally recognised standards. These audits provide assurance that our controls are designed and operating effectively, and that we remain compliant with relevant security and regulatory requirements.

Compliance and independent audits

Business continuity & resilience

Our architecture is designed to survive failure scenarios with minimal disruption to your business.

  • Geo-redundancy: Backups are stored locally for fast recovery and replicated to a secondary EU-based Azure region. This ensures your data remains available even in the event of a total data center loss.
  • Recovery metrics: We maintain a standard data retention period of 14 days, with a target Recovery Time Objective (RTO) of 4 hours during business hours.
  • Validation: Our Disaster Recovery procedures are regularly tested and validated by independent experts, so recovery plans don’t just exist on paper - they work in practice.
Business continuity & resilience

How we approach security

Enterprise-grade infrastructure

Enterprise-grade infrastructure

CreditManager runs on Microsoft Azure’s public cloud, the same infrastructure trusted by global enterprises - and designed to scale with your organisation as it grows. We actively manage and monitor our environment together with Rackspace’s technical experts (Fanatical Support™), so potential issues are identified and resolved before they affect your operations.
  • Availability: We guarantee a 99.8% Uptime SLA.
  • Certifications: Our hosting environment complies with recognised international standards, including ISO/IEC 27001, 27017, 27018, SOC 1, 2 & 3, and PCI DSS Level 1.
Data protection & sovereignty

Data protection & sovereignty

Your data stays yours. We apply strict controls to keep it secure, compliant and aligned with European data protection requirements.
  • GDPR compliance: Full alignment with General Data Protection Regulation standards.
  • Legal safeguards: Clear contractual protection through a Data Processing Agreement (DPA) and Standard Contractual Clauses (SCCs) for lawful international data transfers.
  • Encryption: All data in transit is encrypted via TLS 1.2+ (HTTPS). Customer data is stored in single-tenant databases, preventing any unauthorised access between environments.
Active defence & organisational security

Active defence & organisational security

Security extends beyond servers; it is also about people and processes.
  • Vulnerability management: We regularly perform penetration tests and vulnerability scans to identify and address risks before they can be exploited.
  • Secure connectivity: Optional Site-to-Site VPN (IPsec) enables secure backend connections with your own systems.
  • Personnel security: All employees and contractors are screened through background checks (including Criminal Record Checks) and operate under strict confidentiality agreements (NDAs).
image/svg+xml

Get the
conversation
started

Get the
conversation
started