How we protect your data and keep the OneDash platform secure.
Last updated: 16 July 2026
OneDash protects your data with TLS 1.2+ encryption in transit, AES-256 encryption at rest, comprehensive Role-Based Access Control (RBAC), JWT session management, and data centres located in Johannesburg (primary) and Cape Town (disaster recovery), all POPIA compliant.
OneDash is built from the ground up with security as a core requirement, not an afterthought. Every layer of our stack is designed to protect your business data.
TLS 1.2+ in transit and AES-256 at rest for all data across the platform.
Granular RBAC with module-level permissions and complete audit trails.
South African data centres with 99.9% uptime SLA and disaster recovery.
POPIA and GDPR compliant with formal data processing agreements.
All data transmitted between your browser/app and our servers is encrypted using TLS 1.2 or higher. This includes API calls, webhook payloads, file uploads, and real-time WebSocket connections.
All data stored in our databases and file storage systems is encrypted using AES-256 encryption. This covers messages, contacts, CRM records, invoices, inventory data, knowledge base documents, and media files.
Encryption keys are managed through secure key management infrastructure with automatic key rotation. Access to encryption keys is restricted to essential system processes only.
OneDash implements a comprehensive RBAC system with module-level and action-level granularity:
Every significant action on the platform is logged with full context:
Audit logs are retained for 2 years and are accessible to account administrators.
OneDash operates a multi-tenant architecture with strict data isolation:
We maintain a formal incident response plan that includes:
Full compliance with the Protection of Personal Information Act including data subject rights, breach notification, and Information Officer appointment.
Aligned with EU General Data Protection Regulation requirements for international customers and data transfers.
Compliant with Meta's WhatsApp Business Platform policies for messaging, templates, and opt-in requirements.
Payment processing handled by PCI-DSS compliant partners. OneDash does not directly store card numbers.
We welcome responsible security researchers to report vulnerabilities. If you discover a security issue, please report it to:
We commit to acknowledging reports within 48 hours and providing updates on remediation progress. We will not take legal action against researchers who act in good faith.
For security-related questions or to report a concern: