Resources
We handle payments data for fintechs and platforms processing billions in volume. Security is a first-class part of the product, not a policy binder.
An overview of the security practices at 1Layer — spanning compliance, infrastructure, encryption, and personnel.
SOC 2 controls in place and continuously monitored, plus independent penetration testing.
We've implemented the controls required for SOC 2 Type II and are actively working with an independent auditor.
Our controls are checked continuously with automated compliance tooling — not reviewed once a year.
Independent security researchers run periodic tests covering network and OWASP Top 10 web vulnerabilities.
Every third party handling customer data is vetted for SOC 2 or an equivalent attestation.
Single-tenant infrastructure in our own Google Cloud project — not a shared, multi-tenant environment.
Production workloads run in our own dedicated project — a single-tenant environment, not shared.
Applications run inside a private VPC. Only explicitly exposed services are reachable, via a managed load balancer.
Our primary database runs on a managed service, isolated from application infrastructure, with encrypted connections and backups.
Internal services are reachable only through a private VPN — never exposed to the public internet.
Google Cloud security tooling continuously monitors for malicious activity and unauthorized behavior.
Infrastructure and cluster versions are patched and upgraded automatically.
Modern, boring cryptography — applied everywhere your data lives or moves.
All external traffic is TLS-terminated with modern ciphers. Certificates are auto-provisioned and rotated.
Confidential customer data is encrypted with AES-256; storage is encrypted with a managed key service.
Full-disk encryption is enforced on all company laptops and storage devices.
RSA 2048-bit or stronger, or ECC 256-bit or stronger, signed with SHA-2 or better.
Least-privilege access, full audit trails, and a vetted team handling your data.
Fine-grained permissions control exactly what each user can see and do inside 1Layer.
Every action taken by users or automated agents is logged and attributed.
All staff undergo background checks at onboarding and complete ongoing security training.
Access to customer data follows least-privilege; anything beyond pre-approved roles needs documented approval.
We use essential cookies to make this site work. We don't use tracking or advertising cookies. Privacy Policy