Security

How OneLink looks after your data.

What we do to keep your pages and your readers' details safe, written plainly. If your security team has a questionnaire, send it to us.

Where it runs

OneLink runs on Cloudflare's network. The database, sign-in and uploaded pictures are hosted by Supabase, in the United States. Payments go through Stripe, so card numbers never reach us. Email goes out through Resend. The full list is on our subprocessors page.

Encryption

Every page, dashboard and API call uses HTTPS. Stored data is encrypted at rest by our database provider. Passwords are handled by the sign-in service and are never stored in readable form.

Who can see what

  • Every table in the database has access rules written into the database itself, so a person can only read or change the pages they're on, whatever the app asks for.
  • On Newsroom and Enterprise, each person has a role: admins run the page and its team, editors change it, contributors' work waits for approval, and viewers only look. Subscriber lists, messages and bookings are hidden from contributors and viewers.
  • The activity log records who changed what, on which page, and when, and can be exported.
  • Enterprise teams can sign in through their own identity provider (SAML single sign-on).
  • Secrets you give us, like a CRM key or a webhook address, are kept where only our server can read them. The dashboard never shows them again after you save them.

Visitors to your pages

We count views and taps to show you Insights, without cookies and without identifying anyone. If you add your own analytics (Google Analytics, Meta Pixel, and on Newsroom Adobe, Chartbeat or Parse.ly), visitors in the EU, the UK and Switzerland are asked first and nothing loads unless they agree.

Certifications

OneLink doesn't hold a SOC 2 or ISO 27001 certificate of its own yet. The providers we build on publish their own security and compliance reports, and we're glad to point your team to them.

Paperwork

Enterprise customers get a data processing agreement, our answers to security questionnaires, annual invoices and purchase orders. Ask at support@onelinkin.bio or through the Enterprise page.

Found a problem?

If you think you've found a security issue, email support@onelinkin.bio with the details. We reply to every report, and we won't take action against anyone reporting in good faith.