Skip to content
OneAggrgtr

Security

Every tenant boundary is enforced on the server, not assumed at the edge.

OneAggrgtr is multi-tenant by design. These are the security properties its architecture has been built and exercised against — stated exactly, with what they do not yet cover.

What the architecture does

Built and tested end to end in our own environments.

Tenant-scoped roles, enforced server-side

Every request is checked against the caller's current role grants on the server. Tenant boundaries between organizations, businesses, and locations are never inferred from anything the client sends.

Encrypted credentials

Provider credentials are encrypted at rest, are never returned in API responses, and are never written to logs. Production refuses to start with a known-default encryption secret.

Audited platform-operator access

Platform operators reach tenant data only through explicit, credential-scoped access, and every privileged action leaves an audit record.

Webhook verification, not blind trust

Inbound events are cryptographically verified and deduplicated before anything is persisted or acted on.

What this does not cover

No live provider or customer data is involved yet.

These properties have been exercised against simulated providers and test data in our own environments, not in production against a live provider or real customer data — none exists yet. This page is not a compliance certification, an audit report, or a claim of any third-party attestation. It describes what has been built, not what has been independently verified by a third party.

Have a security question about the architecture?

If you are evaluating OneAggrgtr as a partner or integrator, we are glad to go deeper on any of this.