← Home

Trust, security & privacy

How SaudiEx OneOS protects customer data and what we ask of our customers in return.

Overview

This page is maintained by SaudiEx as the operator of OneOS to answer common security and privacy questions about the OneOS platform. It describes the controls and practices currently in place. It is editable project content and is not an independent certification or third-party audit attestation.

OneOS is delivered as a shared-responsibility service. SaudiEx is responsible for the application, its access controls, and how customer data is handled inside the product. Our underlying hosting providers are responsible for the security of the infrastructure they operate. Customers remain responsible for managing their own user accounts, role assignments, and the data they choose to upload.

Access & authentication

  • Access requires a verified user account. Administrators control who can sign in to each tenant.
  • Permissions are enforced server-side using role-based access control and row-level security policies. The frontend does not grant access on its own.
  • Privileged actions (such as managing roles, finance data, or HR data) are limited to specific administrative roles.
  • Sessions are managed by the authentication provider and can be revoked by signing out or by an administrator removing the account.

Platform & hosting

OneOS runs on managed cloud infrastructure. Traffic to the application is served over HTTPS, and the managed database and authentication services use encryption in transit and at rest as provided by the hosting platform.

Application secrets (API keys, integration tokens) are kept in server-side secret storage and are never shipped to the browser.

Data collection & use

  • We collect the operational data that customers enter into OneOS (for example: tickets, jobs, assets, customers, employees, and related attachments).
  • We process this data to operate the service for the customer that owns it. We do not sell customer data.
  • Sensitive fields such as salary, banking, and national identifiers are restricted by role and are not visible to general staff users.

Subprocessors & integrations

OneOS relies on a small number of trusted subprocessors to deliver the service, including a managed cloud backend (database, authentication, storage, and edge functions) and our hosting provider. Optional integrations (for example GPS providers, biometric devices, SIM providers, or AI features) are only used for tenants that enable them and are configured by the customer.

A current list of subprocessors and their roles can be requested from the contact below.

Cookies & analytics

OneOS uses cookies and similar local storage required to keep users signed in and to remember interface preferences. We do not use these for cross-site advertising.

Retention & deletion

Customer data is retained for as long as the customer's account is active. Customers may request deletion of their tenant's data by contacting us using the address below. Some records may be retained for a limited period to meet legal, accounting, or backup requirements, after which they are removed.

Privacy requests

Individuals whose personal data is processed in OneOS can ask the customer (data controller) that owns the workspace to access, correct, or delete that data. If you are unsure which workspace holds your data, contact us and we will help route the request.

Incident response

If we become aware of a security incident that materially affects customer data, we will notify affected customers in line with applicable law and the terms of their agreement, and work with them on remediation steps.

Report a vulnerability

We welcome responsible disclosure of suspected security issues. Use the form below or email security@one-os.tech. Please do not include real customer data in your report.

0 / 10000

We respond to confirmed reports within 5 business days.

Researchers can also find our contact info at /.well-known/security.txt.

Compliance

OneOS is designed to help customers meet their own compliance obligations. Specific certifications, regulatory attestations, or a Data Processing Addendum can be discussed on request. This page does not itself constitute a certification.