Your operating record, guarded like your people.
EHSQ data is sensitive: incidents, health information, training records, contractor documents, audit evidence and operational risk. Onos treats security as part of the platform, not a procurement appendix.

- ISO 27001
- Cyber Essentials
- GDPR
Granular permissions
Role-based access controls across companies, regions, projects, modules, features and records.
Secure cloud infrastructure
Hosted on Amazon Web Services in data centres with multi-factor authenticated, fully logged physical access, redundant power and backup generation. Cyber Essentials certified, and operated to ISO 27001 controls — the same protocols, systems and methodologies an audited ISMS runs on — so the platform holding your ISO 45001, 14001 and 9001 evidence is run to the same standard.
GDPR by design
Data processing controls, permissions, retention and subject-access support built into the platform.
Encryption everywhere
AWS S3 server-side encryption for every data object and EBS volume encryption at rest. Every connection over HTTPS with TLS; data in transit encrypted to AES-256 with RSA key exchange.
Credentials protected
Passwords hashed with salt in storage and in transit. Granular, role-based permissions govern every module, feature and notification — and every operational record carries an audit trail. Single sign-on and two-factor / multi-factor authentication are coming soon.
Resilience and recovery
Backups, tested recovery and operational continuity disciplines.
Q is powerful because it is constrained.
Q works inside your Onos environment, on your organisation's records. It drafts, flags, scores, explains and chases — but authority stays with your competent people. Every Q output links back to source evidence by design.
Your security team will have questions.
Good. Send them our way — we will provide security documentation, architecture answers and a technical conversation, not a marketing PDF.
hi@onos.app · Security documentation available under NDA












