Security and data

Your data is stored in Australia. Each customer of OntraOS has its own database and its own private file store.

Where your data is

  • OntraOS runs in Microsoft Azure, in the Australia East region (Sydney).
  • Your database and your files are stored in that region.
  • The files are kept in more than one Azure availability zone, so they stay readable when one zone fails.

Each customer's data stays apart

  • Each customer has its own database, with its own database login. That login connects only to that database.
  • Inside the database, row-level security checks the company again on each row.
  • OntraOS takes your company from your sign-in, never from a value in the request.
  • Each customer has its own private file container. A phone or browser gets a file only after sign-in and a permission check, through a link that works for one file and for 5 minutes.
  • The database has no public address. Only the OntraOS servers in Azure connect to it.
  • Passwords and keys for the servers are kept in Azure Key Vault.
  • This website is separate from the app and from your files. It holds no customer data.

Sign-in and access

  • Two-factor sign-in for each person. An owner can make it required for the whole company.
  • Sign in with Microsoft or Google, followed by OntraOS's own two-factor sign-in.
  • Roles and permissions decide who sees costs, prices and private details.
  • The audit log records every change, with who made it and when.
  • API keys have scopes, an expiry date and an optional list of allowed addresses.

When something fails

  • Two app servers run in two Azure availability zones. Each one serves customers every day. When one server fails, the other takes its customers.
  • A new version goes to our own company first, then to chosen customers. A customer can go back to the earlier version without data loss.
  • High availability is an option. With it, your database has a standby copy in a second zone. The standby gets every change before the change is confirmed, and it takes over by itself when the first zone fails.
  • Without high availability, your database is restored from its point-in-time backup when its server fails.

Backups and history

  • Point-in-time restore of each database, to the second, for 7 to 35 days.
  • A copy of each customer's database every night, kept for 7 days, 4 weeks and 12 months.
  • Earlier versions of each file, and a recycle bin that keeps deleted files for 30 days.
  • OntraOS tests its backups by restoring them.
  • 7-year keeping is an option. Each month a locked, encrypted copy of your data goes to an archive in Sydney and Melbourne. Nobody can change or delete it for 7 years.

Your data is yours

  • An owner can download all of the company's data and files as one zip file at any time.
  • The export leaves out passwords, keys and each person's private email.

Questions about security? Contact us.