Trust - Security & Privacy - Own

Trust

Own Company takes privacy and security very seriously. Our platform was built from the ground up with security in mind utilizing leading information security best practices.

Compliance

Own implements best practices and industry standards to achieve compliance with numerous leading information security certifications and authorizations. View our technical and regulatory certifications below.

SOC 2 Type 2

Own receives an annual SSAE 18 SOC 2 Type II attestation report to provide assurance to our customers and partners that Own uses secure systems and processes to protect their data.

Own's latest SOC 2 Type II report is available upon request under NDA.

SOC 1 Type 2

Own receives a SSAE 21 SOC 1 Type II attestation report to provide assurance to our customers and partners that Own implements effective internal controls over financial reporting.

Own's latest SOC 1 Type II report is available upon request under NDA.

FedRAMP Authorized

Own achieved FedRAMP authorization for its Own Government Cloud solution. With this authorization, Own is now listed on the FedRAMP Marketplace, and is eligible to provide data protection services to all U.S. Federal Government customers. Learn more

ISO

Own is ISO 27001:2013 and ISO 27701:2019 certified, demonstrating Own has implemented best-practice information security and privacy processes to securely provide services to our customers.

ISO 27001:2013 Certificate

Information Security Management System (ISMS) Download here.

ISO 27701:2019 Certificate

Privacy Information Management System (PIMS) Download here.

Hébergeur de Données de Santé (HDS)

The HDS certification requires cloud service providers that host personal data governed by French laws to implement strong security measures to protect health data.

Own's HDS certification demonstrates our commitment to securing and protecting the confidentiality of personal health data.

Additional information on Own’s HDS program can be found here.

HDS Certification (English)

HDS Certification (French)

Cyber Essentials UK

Own is Cyber Essentials certified to comply with UK government requirements for implementing the Cyber Essentials Schema of security controls to support our UK government clients that handle personal information.

Own's Cyber Essentials certification can be downloaded here.

EU General Data Protection Regulation (GDPR)

If you are capturing and storing personal information of European Citizens, your company may be held liable under the GDPR, an EU data protection and privacy regulation. Own products are designed to support our customer's compliance obligations with data privacy regulations, including GDPR requirements.

More information on Own’s GDPR compliance capabilities can be found here.

Data Privacy Framework

Own is registered under the EU-U.S. Data Privacy Framework (EU-U.S. DPF), UK Extension to the EU-U.S. DPF, and Swiss-U.S. DPF, demonstrating adequate data protection controls are implemented for cross-border transfers of personal data in compliance with EU law.

Own’s EU-U.S. DPF, Swiss-U.S. DPF and UK Extension to the EU-U.S. registration details can be found here.

Health Insurance Portability and Accountability Act (HIPAA) / Health Information Technology for Economic and Clinical Health (HITECH)

To support the compliance programs for our Healthcare clients, Own extended the SOC 2 Type 2 audit scope to include applicable HIPAA/HITECH controls to demonstrate adequate safeguards are in place to protect healthcare data. Own’s latest HIPAA/HITECH report is available upon request under NDA.

Quality Management System (QMS)

Own’s QMS ensures our products are designed, developed, and maintained using industry-leading infrastructure, processes, and tools to deliver the highest levels of quality and ensure security of the product environment storing our customer’s data.

Own mapped our QMS against applicable 21 CFR Part 11 (“GxP”) and EudraLex Volume 4, Annex 11 (“GmP”) controls to externally validated controls within our ISO 27001 certification and SOC 2 Type II report to support the compliance program of our Life Sciences clients.

Additional information for Own’s support for GxP and GmP compliance can be found here.

Professional Membership

Cloud Security Alliance (CSA)

Our customers trust us with their most valuable asset-their data. We don’t take that responsibility lightly, which is why we are always looking to enhance our commitment to security. Built upon existing Cloud Security Alliance programs, the Trusted Cloud Provider program demonstrates an organization’s commitment to holistic security and serves as a reference point for customers looking to identify cloud providers aligned with their security requirements.

Own is an official Cloud Security Alliance (CSA) partner demonstrating our dedication to being a trusted cloud provider.

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products.

Information Systems Audit and Control Association (ISACA)

Own security personnel are part of the ISACA network, one of the world’s largest global organizations for information security professionals, and frequently participate in knowledge sharing to provide insight into emerging security threats and help advance the security field.

International Information System Security Certification Consortium (ISC2)

Own security personnel hold numerous ISC2 security certifications, including the Certified Information System Security Professional (CISSP), and are active members in the ISC2 community. ISC2 is a leading organization specializing in training and certifications for cybersecurity professionals.

New Jersey Cybersecurity and Communications Integration Cell (NJCCIC)

Own is a member of the NJCCIC and receives cyber alerts and advisories, cyber tips and best practices for managing cyber risk. The NJCCIC provides members with cyber information sharing, cyber threat analysis, and incident reporting services to promote statewide awareness of cyber threats and the adoption of best practices.