Security and data
Your data is stored in Australia. Each customer of OntraOS has its own database and its own private file store.
Where your data is
- OntraOS runs in Microsoft Azure, in the Australia East region (Sydney).
- Your database and your files are stored in that region.
- The files are kept in more than one Azure availability zone, so they stay readable when one zone fails.
Each customer's data stays apart
- Each customer has its own database, with its own database login. That login connects only to that database.
- Inside the database, row-level security checks the company again on each row.
- OntraOS takes your company from your sign-in, never from a value in the request.
- Each customer has its own private file container. A phone or browser gets a file only after sign-in and a permission check, through a link that works for one file and for 5 minutes.
- The database has no public address. Only the OntraOS servers in Azure connect to it.
- Passwords and keys for the servers are kept in Azure Key Vault.
- This website is separate from the app and from your files. It holds no customer data.
Sign-in and access
- Two-factor sign-in for each person. An owner can make it required for the whole company.
- Sign in with Microsoft or Google, followed by OntraOS's own two-factor sign-in.
- Roles and permissions decide who sees costs, prices and private details.
- The audit log records every change, with who made it and when.
- API keys have scopes, an expiry date and an optional list of allowed addresses.
When something fails
- Two app servers run in two Azure availability zones. Each one serves customers every day. When one server fails, the other takes its customers.
- A new version goes to our own company first, then to chosen customers. A customer can go back to the earlier version without data loss.
- High availability is an option. With it, your database has a standby copy in a second zone. The standby gets every change before the change is confirmed, and it takes over by itself when the first zone fails.
- Without high availability, your database is restored from its point-in-time backup when its server fails.
Backups and history
- Point-in-time restore of each database, to the second, for 7 to 35 days.
- A copy of each customer's database every night, kept for 7 days, 4 weeks and 12 months.
- Earlier versions of each file, and a recycle bin that keeps deleted files for 30 days.
- OntraOS tests its backups by restoring them.
- 7-year keeping is an option. Each month a locked, encrypted copy of your data goes to an archive in Sydney and Melbourne. Nobody can change or delete it for 7 years.
Your data is yours
- An owner can download all of the company's data and files as one zip file at any time.
- The export leaves out passwords, keys and each person's private email.
Questions about security? Contact us.