
One More Cloud and GDPR
CertReports found no public GDPR evidence for One More Cloud as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 28 Jan 2020
- Expires or valid through
- 4 Aug 2027
- Scope
- One More Cloud builds and maintains a data platform for its customers. As such, we are entrusted with our customers' data, and it's possible that our customers are trusting us with data they consider to be both private and valuable. OMC seeks to earn our customer's trust by providing a secure environment at all levels of the platform. Our security footprint includes any application that we are building, any data that we receive from our customers, as well as our own internal communications and private source code. All OMC employees should store passwords and other credentials in a secure system such as 1Password. All employees have access to the company 1Password account, and that account is subdivided into multiple Vaults that allow access only to people with the need. All OMC laptops have "FileVault" turned on, this is the macOS hard drive encryption feature. This combined with JAMF's ability to ensure a strong password means that our machines are protected at rest. OMC deploys a Zero Trust network. All network requests must be authenticated. Either by a web app asking for OAuth with Google, or using standard issue username/password challenges. No access is granted by simply being in the "network." As a part of our defense-in-depth, whenever possible select the MFA option on sensitive systems. Providing a 3rd vector of authentication makes compromising our systems that much harder. All customer data is backed up each hour. All customer data is protected by Nespr or Webr our in-house proxies (which also act as a WAF), which require all access to be authenticated using HTTP Basic Authentication. Additionally, all Elasticsearch clusters are protected by the Bonsai Plugin which requires authentication as well. When it comes to source code, OMC does maintain a policy of contributing to OSS, and requests to support OSS are generally well received. OMC maintains a Zero-Trust network, such that every request to any OMC asset will require some form of authentication verification. For our internal systems that is going to be an OAuth challenge back to Google before being granted access. For our Elasticsearch servers that is going to be a Basic Auth challenge before being granted access. For most other services there will be a standard issue Username + Password challenge. OMC encrypts all customer data both in-transit and at-rest. OMC is SOC2 Type ll certified and has been for the past 4 years. One More Cloud, Inc. discloses personal data received in reliance on the EU-U.S. DPF to the following categories of third parties: cloud infrastructure, database, and application hosting providers (Amazon Web Services, Google Cloud, and Heroku for customers using the Heroku Add-On); customer relationship management (HubSpot); support ticket communication (Plain); transactional email delivery (ActiveCampaign Holdings d/b/a Postmark); billing automation (Stripe); product analytics and usage measurement (Google Analytics, Amplitude); and customer feedback tooling (Jimo). These third parties process personal data solely to provide services on One More Cloud's behalf and are contractually bound to protect it consistent with the DPF Principles
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | One More Cloud: Active: EU-US Certification | Live pagesha256 cb291b7b89 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is One More Cloud GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Data platforms category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Data platforms vendor has GDPR evidence in the index yet.