Security Overview
Security is central to how we build and run OmniSaaSy. This overview summarises the controls we have in place to protect the data our Customers trust us with. It is written for a general audience; more detailed documentation, including our ISO/IEC 27001 certificate and control summaries, is available to Customers and prospects under confidentiality as part of due diligence.
Last updated: 16 July 2026
Certification and governance
The SaaSy People Ltd operates an information security management system certified to ISO/IEC 27001. Security is owned at executive level and roles, responsibilities and reporting lines are documented within our management system. We are registered with the UK Information Commissioner's Office under registration number ZB066023.
Encryption
- In transit. All data is encrypted using TLS 1.2 or higher. There are no plain HTTP endpoints in production; HTTP traffic is redirected to HTTPS with HSTS applied.
- At rest. Sensitive fields in the production database are encrypted with AES-256, and backups are encrypted at rest with AES-256.
Access control
Access to production environments is restricted to a small number of named, authorised personnel on a least-privilege basis. Multi-factor authentication is enforced on production and administrative accounts, access is granted through a documented change process, reviewed regularly, and revoked promptly on role change or departure through our offboarding checklist. Employee access to Customer data is logged.
Hosting and infrastructure
Primary hosting is provided by Hetzner in ISO/IEC 27001 certified data centres in Nuremberg, Germany (EEA), with 24/7 staffed access control, biometric entry, CCTV and intrusion detection. Encrypted backups are stored with Amazon Web Services in the London region (UK); AWS operates to ISO/IEC 27001 and SOC 1, 2 and 3. No Customer data is stored on internal company hardware.
Monitoring
Infrastructure is monitored with automated uptime and error-rate monitoring at the application and hosting layers. We perform regular reviews of server health, patching status and privileged access logs, and critical alerts route to our engineering team.
Backups and resilience
Backups are taken daily. Full-server image backups are supplemented by encrypted application and database exports held in the London region. Backup integrity is monitored and restoration is tested periodically. Our documented business continuity and disaster recovery plan is reviewed and tested at least annually, with a Recovery Time Objective of 72 hours and a Recovery Point Objective of 24 hours. We target 99.5% monthly availability for the core service.
Data residency
Primary processing and administration take place within the EEA and UK. Where a Customer connects third-party platforms, those providers may process data outside the EEA and UK under recognised transfer mechanisms, as described in our Privacy Policy and Data Processing Agreement.
People and awareness
All employees complete pre-employment checks during onboarding, including right-to-work verification and reference checks. Everyone is bound by contractual confidentiality obligations. Security awareness training, including phishing simulations and data-handling modules, is completed on onboarding and annually, with completion tracked and reviewed.
Supplier management
We carry out due diligence on sub-processors at onboarding and review them at least annually as part of our ISO/IEC 27001 supplier management process. Reviews consider assurance reports (such as SOC 2 and ISO/IEC 27001), data protection terms, data residency and incident history, and contractual data protection obligations flow down to each sub-processor.
Vulnerability and incident management
Bugs and security vulnerabilities, whether reported by customers or identified internally through monitoring and dependency scanning, are triaged by our engineering team, with critical issues prioritised for prompt remediation. Security incidents are handled under our ISO/IEC 27001 incident management procedure, which captures detection, impact, containment, remediation and lessons learned, and all incidents are recorded in a central register. Where a personal data breach affects Customer data, we notify the affected Customer without undue delay and in any event within 72 hours of becoming aware.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please contact [email protected] so we can investigate and respond.