OUR APPROACH
Security is foundational to OneBlink's product. Our core service is the safe provisioning and complete destruction of isolated cloud environments. The same architecture that makes our sandboxes useful, strict isolation, minimal data collection, and automatic teardown, is what keeps our customers and workshop participants safe.
INFRASTRUCTURE AND ISOLATION
- Dedicated accounts per sandbox: every sandbox environment is provisioned in its own dedicated cloud account within an AWS Organizations multi-account architecture. There is no shared tenancy between participants or customers.
- Ephemeral by design: environments are provisioned for the duration of a workshop or engagement and are fully destroyed afterward, including all data, resources, and access grants.
- Federated, time-limited access: participants access environments through federated sessions (AWS STS) with scoped permissions and automatic expiry. We do not issue long-lived credentials to participants.
- Guardrails: sandbox accounts operate under organization-level service control policies and resource restrictions that limit blast radius.
DATA PROTECTION
- Minimal collection: we collect only business contact information (name, email) needed to provision access. We do not collect or store payment card data or sensitive personal information.
- Encryption: all data is encrypted in transit (TLS 1.2+) and at rest.
- No secondary use: sandbox contents are never used for analytics, AI training, or service improvement, and are permanently deleted at environment teardown.
- Subprocessors: a current list of third-party service providers is published at oneblink.ai/oneblink_subprocessors.html.
LOGGING AND MONITORING
- Centralized audit logging: AWS CloudTrail is enabled across all accounts in our organization, with logs aggregated centrally for audit and investigation.
- Continuous benchmark scanning: we scan our cloud estate against CIS benchmarks using automated tooling (Prowler) and remediate findings.
- Cost and resource anomaly monitoring: automated monitoring detects unexpected resource usage in sandbox accounts, which serves as both a cost control and an abuse detection mechanism.
ACCESS CONTROL
- Least privilege: IAM policies follow least-privilege principles across the organization.
- MFA: multi-factor authentication is enforced for administrative access to our cloud environments.
- Separation: production infrastructure, customer workshop accounts, and internal development are separated at the account level.
COMPLIANCE AND ASSURANCE
- AWS Foundational Technical Review (FTR): OneBlink's platform has been reviewed and approved under the AWS FTR program, which validates architecture against AWS Well-Architected security best practices.
- Insurance: OneBlink maintains Technology Errors & Omissions and Cyber Liability insurance with USD $2,000,000 limits.
- Vendor security assessments: we participate in customer and partner security review processes and can provide supporting documentation under NDA on request.
ORGANIZATIONAL SECURITY
- Security is a founder-led function with direct ownership of architecture, operations, and incident response.
- Incidents affecting customer data are investigated promptly, and affected customers are notified without undue delay in accordance with applicable law and contractual commitments.
RESPONSIBLE DISCLOSURE
If you believe you have found a security vulnerability in any OneBlink service, we want to hear from you. Please report it to security@oneblink.ai with enough detail for us to reproduce the issue. We ask that you do not access data that is not yours, degrade the service, or publicly disclose the issue before we have had a reasonable opportunity to address it. We will acknowledge reports promptly and keep you informed as we investigate.