Encryption
All traffic uses TLS 1.2+. Databases and file storage are encrypted at rest. API keys and session tokens are hashed, never stored in plaintext.
Security
Oceanir is designed for teams handling visual evidence, review files, and procurement review. SOC 2 Type II is in progress. Data is encrypted in transit and at rest, payments run through Stripe, and audit logs are available on paid workspaces. Annual contracts are available through sales.
All traffic uses TLS 1.2+. Databases and file storage are encrypted at rest. API keys and session tokens are hashed, never stored in plaintext.
Better Auth powers email/password, Google OAuth, and passkeys (WebAuthn). Cloudflare Turnstile guards against automated abuse. Rate limiting applies to all auth endpoints.
Pro and Unit workspaces support activity trails for review, evidence handling, and internal accountability. Logs are exportable for compliance reviews.
Uploads are processed for verification workflows with access controlled through account, team, and enterprise permissions. Data is stored in US-region infrastructure and can be deleted on request.
All payment processing is handled by Stripe. Oceanir never touches, stores, or transmits raw card data. Stripe is PCI DSS Level 1 certified.
SSO/SAML, annual contracts, invoicing, and dedicated deployment discussions are available through sales.