Data Security
We work tirelessly to keep your data as secure as possible. We implement the following procedures/best practices to the best of our abilities and constantly looking to improve our security:
Infrastructure and Application Security
Section titled “Infrastructure and Application Security”- We leverage cloud firewall security to protect against external threats, DDOS attacks (see Cloudflare below)
- Our servers are managed by a best of class security vendor (see DigitalOcean below)
- All sensitive data is stored at rest using bank level encryption (AES 256 GCM)
- Passwords are one way hashed (can’t be decrypted) and require email verification to update
- Configuration keys/passwords for production environment are not stored in any public/private repositories, and only maintained by very limited group of senior employee(s).
- Database is locked down by firewall with extremely strict access
- Servers have no root access
- Server and codebase libraries are kept up to date as security holes are discovered (if any)
- Database has no SSH direct access and managed by top level secure 3rd party (see DigitalOcean below)
- All servers require HTTPS access only. TLS 1.2 is used wherever possible
- Client communication after login utilizes secure, limited use cookie hash communication
This list may not be exclusive of all security best efforts being used. We regularly audit our security measures and are constantly looking to improve them as needed.
Vendor Security we rely upon:
- Cloudflare
- DigitalOcean
Account Security and Two-Factor Authentication
Section titled “Account Security and Two-Factor Authentication”Two-factor authentication (2FA) is available on every On2Air account, on every plan, at no additional cost. 2FA uses time-based one-time passwords (TOTP) with a standard authenticator app such as Google Authenticator or Microsoft Authenticator.
- How to enable Two-Factor Authentication on your account
- Team members are managed through the Admin panel with role-based access, so you control who on your team can view or change backup configuration
- Internally, On2Air employee access to production systems requires multi-factor authentication and is limited to the specific access a role requires
Confidentiality of Your Content
Section titled “Confidentiality of Your Content”We treat your content — your Airtable data, your account information, and your configuration — as confidential information. We do not sell it, and we do not disclose it to third parties except:
- to the sub-processors we rely on to operate the service (listed in Annex III of our Data Processing Addendum), each of which is bound by equivalent data protection obligations;
- where you direct us to, such as writing your backup files to your own cloud storage account; or
- where we are required to by law.
On2Air personnel who are authorized to access customer data have committed to confidentiality obligations, and access is limited to the small number of senior personnel who need it to operate the service or to resolve a support request you have raised.
What We Store
Section titled “What We Store”To operate On2Air Backups, we store on our own systems:
- Your account and billing details (name, email, company, subscription state)
- Your Airtable connection credentials (OAuth tokens or API keys), encrypted at rest
- Your cloud storage connection credentials (Google Drive, Dropbox, Box, OneDrive), encrypted at rest
- Airtable structural metadata — base, table, and field names, field types, and IDs — which we need in order to build your backup files and show you what will be backed up
- Backup job configuration, schedules, and run logs
Your record content and attachments are read from Airtable and written to your own cloud storage account. That content passes through our systems only for as long as it takes to complete the transfer, and is not kept on On2Air servers as a retained copy of your data. On2Air is not a data warehouse — we do not maintain a queryable store of your record contents.
Security Incident Notification
Section titled “Security Incident Notification”If we become aware of a security incident affecting your data, we will notify you without undue delay. Our notification will include what we know at the time about the nature of the incident, the data and accounts affected, the steps we have taken, and what (if anything) we recommend you do. We will keep you updated as our investigation progresses. This commitment is also a contractual obligation under Section 7 of our Data Processing Addendum.
To report a suspected vulnerability or security issue to us, email support@on2air.com with “Security” in the subject line.
Data Retention and Deletion
Section titled “Data Retention and Deletion”- We retain your data only for as long as needed to provide the service and to meet legal, accounting, and tax obligations.
- On termination, or at your request at any time, we will delete your data from On2Air systems — including your Airtable and cloud storage credentials, your stored metadata, and your job history.
- Backup files that have already been written to your own cloud storage account (Google Drive, Dropbox, Box, OneDrive) remain in your account, under your control. Once your On2Air account is deleted we no longer have any access to those accounts, so deleting or retaining those files is your decision to make.
- To request deletion, email support@on2air.com.
We Do Not Use Your Data to Train AI Models
Section titled “We Do Not Use Your Data to Train AI Models”We do not use your content, your Airtable data, or your metadata to train, fine-tune, or evaluate artificial intelligence or machine learning models, and we do not make it available to any third party for that purpose.
Compliance and Certifications
Section titled “Compliance and Certifications”- GDPR — We act as a data processor for the customer data we handle. Our Data Processing Addendum sets out our processor commitments and lists our current sub-processors.
- SOC 2 — We are actively working toward SOC 2 Type II. We are not certified today, and we will update this page when that changes. In the meantime, our Technical and Organizational Measures document our full control set, and we are happy to complete your security questionnaire.
- ISO 27001 — On2Air does not hold an ISO 27001 certification. The infrastructure providers we build on, Cloudflare and DigitalOcean, each maintain SOC 2 Type II and ISO 27001 certifications for the platforms and facilities that host On2Air.
- PCI-DSS — We never store payment card details. Payment information goes directly to our PCI-DSS compliant payment processor.
Related Documents
Section titled “Related Documents”- Data Processing Addendum (DPA) — our GDPR processor commitments, including the current sub-processor list
- Technical and Organizational Measures (TOMs) — the detailed control set behind Annex II of the DPA
- Privacy Policy
- Cookie Policy
- Terms of Use
Email support@on2air.com if you need a countersigned copy of the DPA for your records, or a completed security questionnaire for your review process.