Source
Security / trust page — OnePageCRM
Checked for OnePageCRM on 30 Sep 2026
- Page
- https://www.onepagecrm.com/security-2/
- Checked
- 30 Sep 2026, 11:38 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:acd42a12cd8c7182c8cfff301ff47d9741a4f9a34d1780b443195caf913579a0
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Pen testing annual Report an error
“OnePageCRM undergoes an annual security assessment by a world-renowned security audit company which consists of comprehensive penetration testing including”
-
Vdp Report an error
“OnePageCRM also has an active Vulnerability Disclosure Program.”
-
Encryption in transit Report an error
“all traffic is encrypted in transit via HTTPS with a minimum supported TLS version of 1.2 and with a modern set of cipher suites recommended by Mozilla”
-
Ssl grade Report an error
“We are graded A+ in the Qualys SSL Server Test.”
-
Encryption at rest Report an error
“it is stored encrypted at rest. This is done using the industry-standard AES-256 algorithm.”
-
Password hashing Report an error
“Passwords are salted and hashed with SHA256.”
-
Owasp aws frameworks Report an error
“Ensuring compliance with OWASP security principles and AWS Shared Responsibility Model and other relevant security frameworks to ensure sanctity of users’ data.”
-
Provider Report an error
“OnePageCRM uses a top-tier, third-party data hosting provider Amazon Web Services (AWS).”
-
Regions Report an error
“OnePageCRM uses AWS servers located in North Virginia, U.S., and Dublin, Ireland to store your data.”
-
Scc transfers Report an error
“OnePageCRM relies on Standard Contractual Clauses (SCCs) included in the AWS GDPR Data Processing Addendum.”
-
Scc Report an error
“OnePageCRM uses the Standard Contractual Clauses with all of our sub-processors based outside the EEA.”
-
Aws SOC 2 Report an error
“AWS also provides a SOC 2 report for their cloud computing service.”
-
Backup schedule Report an error
“We back up your data on a nightly basis. All backups are replicated to another AWS region for redundancy and fault tolerance purposes.”
-
Backup retention Report an error
“These backups are stored in a readily recoverable state for a two-week period before being put in cold storage for another 90 days at which point they are fully deleted.”
-
Deleted account backup window Report an error
“Once your OnePageCRM account has been deleted, it can remain in backups for up to 114 days.”
-
Self delete Report an error
“OnePageCRM does not have the ability to delete your account. You may delete your own account by following the instructions here.”
-
Breach notification Report an error
“We comply with GDPR requirements to report any incidents to our controllers and any affected parties within 72 hours.”
-
Uptime Report an error
“We maintain over 99.9% uptime for our services.”
-
Rto rpo Report an error
“the recovery point objective (RPO) is to the last daily backup and the recovery time objective (RTO) is 6 hours.”
-
User types Report an error
“OnePageCRM provides four types of users to ensure appropriate access: Account Owner, Administrator, User and Focused User.”
-
Two factor auth Report an error
“Turn on two-factor authentication for your users.”
-
Incident response plan Report an error
“OnePageCRM has an incident response procedure in place. Incident response training is conducted on a regular basis. The incident response plan is reviewed annually.”
-
Integrations API Report an error
“CRM Integrations API”