OnRamp has stringent controls in place that comply with industry recognized standards for the security and protection of sensitive, critical data. OnRamp participates in regular third party audits that include controls over information technology and related processes, policies, procedures and operational activities. These audits and certifications validate that OnRamp is performing at optimal standards regarding security, availability and operating integrity.
The Statement on Standards for Attestation Engagements no. 16 (SSAE 16) is the new “attest” standard put forth by the Auditing Standards Board (ASB) of the American Institute of Certified Public Accountants. Formerly known as “SAS 70,” an SSAE 16 audit includes controls over information technology and related processes, policies and procedures, including operational activities, and validates everything is performing at optimal standards regarding security, availability and operating integrity. As an SSAE 16 SOC I Type II certified company, OnRamp been audited by a third party on our control activities related to:
- Logical and Physical Access
- Security of Environment and Information
- Secure Storage
As HIPAA implementation experts, OnRamp partners with businesses to ensure HIPAA compliance. We have created systems, tools and procedures that help our customers tightly integrate our products and services with their own assets and procedures in a HIPAA-compliant fashion. Our goal is to eliminate the seams and gaps in protection that might otherwise occur. As your trusted partner in the HIPAA implementation process, OnRamp will work with you to design, implement and secure your systems and applications. OnRamp can act as your subject matter expert on what HIPAA requires, letting you remain focused on the day-to-day responsibilities of your core business.
OnRamp assists customers that transmit cardholder information with PCI compliance requirements. Using our experience building and deploying complex IT infrastructure for hundreds of companies, OnRamp works with customers to create PCI compliant solutions to accomplish all 12 of the PCI-DSS 2.0 requirements.
Additional Areas of Regulatory Focus:
- The Gramm Leach Bliley Act (GLBA)
- The Sarbanes Oxley Act (SOX)
- The Fair and Accurate Credit Transaction Act (FACTA)
- The Family Educational Rights and Privacy Act (FERPA)
- The Federal Information Security Management Act (FISMA)
- SEC Cybersecurity Threats Disclosure Guidance