Resources

Security at 1Layer.

We handle payments data for fintechs and platforms processing billions in volume. Security is a first-class part of the product, not a policy binder.

SOC 2 Type II
Audit in progress — controls in place and continuously monitored
AES-256 encryption
Customer data encrypted at rest and in transit
Single-tenant Google Cloud
Dedicated project on our own Google Cloud infrastructure
24/7 threat monitoring
Continuous monitoring across our Google Cloud environment

How we protect your data.

An overview of the security practices at 1Layer — spanning compliance, infrastructure, encryption, and personnel.

Compliance & certifications

SOC 2 controls in place and continuously monitored, plus independent penetration testing.

SOC 2 Type II (audit pending)

We've implemented the controls required for SOC 2 Type II and are actively working with an independent auditor.

Continuous control monitoring

Our controls are checked continuously with automated compliance tooling — not reviewed once a year.

Penetration testing

Independent security researchers run periodic tests covering network and OWASP Top 10 web vulnerabilities.

Audited sub-processors

Every third party handling customer data is vetted for SOC 2 or an equivalent attestation.

Infrastructure & network security

Single-tenant infrastructure in our own Google Cloud project — not a shared, multi-tenant environment.

Dedicated Google Cloud project

Production workloads run in our own dedicated project — a single-tenant environment, not shared.

Private by default

Applications run inside a private VPC. Only explicitly exposed services are reachable, via a managed load balancer.

Managed Postgres database

Our primary database runs on a managed service, isolated from application infrastructure, with encrypted connections and backups.

VPN-gated internal access

Internal services are reachable only through a private VPN — never exposed to the public internet.

24/7 threat detection

Google Cloud security tooling continuously monitors for malicious activity and unauthorized behavior.

Automated patching

Infrastructure and cluster versions are patched and upgraded automatically.

Encryption

Modern, boring cryptography — applied everywhere your data lives or moves.

Encryption in transit

All external traffic is TLS-terminated with modern ciphers. Certificates are auto-provisioned and rotated.

Encryption at rest

Confidential customer data is encrypted with AES-256; storage is encrypted with a managed key service.

Endpoint encryption

Full-disk encryption is enforced on all company laptops and storage devices.

Web certificates

RSA 2048-bit or stronger, or ECC 256-bit or stronger, signed with SHA-2 or better.

Access controls & personnel

Least-privilege access, full audit trails, and a vetted team handling your data.

Role-based access in-product

Fine-grained permissions control exactly what each user can see and do inside 1Layer.

Full audit trail

Every action taken by users or automated agents is logged and attributed.

Background checks & training

All staff undergo background checks at onboarding and complete ongoing security training.

Least-privilege staff access

Access to customer data follows least-privilege; anything beyond pre-approved roles needs documented approval.