Security
How We Protect Your Data
At ONAP, we are committed to protecting your business data and maintaining the security of our platform. We use appropriate technical and organisational measures to protect information, secure our infrastructure, and minimise the risk of unauthorised access, loss, misuse, or disclosure.
How We Protect Your Data
All data transmitted between your browser and ONAP is protected using HTTPS/TLS encryption to help keep information secure during transmission.
Payment processing is handled entirely through Stripe, a PCI-DSS Level 1 certified payment provider. ONAP does not store your full payment card details.
Access to customer data is restricted to authorised personnel where access is required for legitimate business purposes and on a need-to-know basis.
We regularly review and update our security measures and infrastructure to help maintain the protection of customer information.
Account Security
You can help protect your ONAP account by following these security practices:
- Use a strong, unique password for your ONAP account.
- Enable any available two-factor authentication options.
- Contact us immediately at info@onap.uk if you suspect unauthorised access to your account.
Reporting a Security Concern
If you discover a potential security vulnerability affecting ONAP or our services, please report it to us rather than disclosing the vulnerability publicly.
You can report a security concern by contacting us at info@onap.uk . We take all security reports seriously and will review and respond to reported concerns promptly.
Incident Response
In the unlikely event of a data breach affecting your personal data, ONAP will take appropriate steps to assess, contain, investigate, and remediate the incident.
Where required under UK GDPR, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of a qualifying personal data breach.
Where the incident is likely to result in a high risk to affected individuals, we will also notify affected users in accordance with applicable UK GDPR requirements.