Compliance & certifications

The audited standards the infrastructure behind your project is held to.

Your project runs on infrastructure that carries the security certifications most businesses never see up close. We don't rebuild that foundation. We build on platforms already audited to the standards below, so your data inherits their protection from the first day it exists.

Standards the platforms are certified to

  • ISO/IEC 27001, the international benchmark for managing information security.
  • SOC 2 Type 2, independently audited controls for security, availability, and confidentiality, tested over a period rather than a single day.
  • ISO/IEC 27017 and 27018, cloud-specific security and the careful handling of personal data in the cloud.
  • PCI-DSS, card payments run through Stripe, so card numbers never touch our systems.

For regulated work

Healthcare and other regulated clients are built on HIPAA-eligible infrastructure, with the right agreements in place before any protected information is handled. Sites are built to WCAG 2.2 AA accessibility, and personal data is handled in line with GDPR and CCPA.

What this means for you

OnCall is a studio, not itself an ISO- or SOC-audited organisation, these certifications belong to the established platforms your project is built on. What that means is concrete: the systems holding your data are audited to recognised standards, independently and on a schedule, and you can verify each one at its source.

All documentation · Book a Call