← OnPar home
Security & compliance
Built for records that get audited.
Your controlled-substance ledger is evidence. This page is the plain-English version of how we protect it — written so you can hand it to an IT director or a purchasing office without a follow-up call.
Where your data lives
- Encrypted in transit and at rest. TLS on every connection; storage encryption at the database and object-storage layer.
- Per-department isolation enforced at the database layer — row-level security, not application-layer filtering. One department cannot reach another's records even if application code is wrong.
- Role-based permissions down to the capability, with narcotics access granted separately from everything else.
- Regular automated backups, with point-in-time recovery on the database.
- United States hosting for the database, file storage, and web tier.
Controlled-substance records specifically
- Append-only custody ledger. Counts, signatures, seal verifications, administrations, and waste events cannot be edited or deleted through the app by any user, including a department administrator and including us.
- Corrections are new entries, not overwrites — the original record and the correction both survive, each stamped with who and when.
- Numbered tamper-evident seals are single-use forever — the database rejects a reused seal number rather than trusting policy to prevent it.
- Two signatures on every count, tied to individual accounts, with an optional single point-in-time GPS stamp on the signature.
- Tamper-evident audit chain you can verify from the admin console.
- Deletion requires your chief's signed instruction — it is not a self-serve button, deliberately.
What we do not claim
No software is “DEA-approved” or “DEA-certified” — the DEA does not certify recordkeeping products, and any vendor telling you otherwise is wrong. What we do is keep records in the form 21 CFR 1304 expects and make them readily retrievable for an inspection. Compliance remains your department's legal responsibility; OnPar is the tool that makes it defensible.
Subprocessors
The complete list. Each is contractually limited to providing its service to us.
| Provider | What it does | Data it touches |
| Supabase | Database, authentication, file storage | All department records |
| Netlify | Web and app hosting, website forms | Requests; form submissions |
| Apple | Push-notification delivery | Device token, notification text |
| Anthropic, Google | One-shot label-scan processing | A single camera frame, processed and discarded — not stored |
| Resend | Transactional email (sign-in links, briefings) | Name, work email |
What we don't do
- No third-party analytics, advertising, or tracking SDKs in the app — and no advertising identifiers.
- No sale of data, ever, and no data brokers.
- No patient health information. Controlled-substance entries instruct crews to use age and initials only. The product is not designed to hold PHI and our Acceptable Use Policy prohibits submitting it.
- No continuous location tracking. The only location data is the optional one-time GPS stamp on a custody signature.
- Face ID never leaves the device — biometric matching happens entirely in Apple's secure enclave; we receive a yes or no.
Certifications — where we honestly stand
We are a young company and we will not imply otherwise. OnPar does not currently hold a SOC 2, ISO 27001, StateRAMP, or FedRAMP attestation. The controls above are real and in production today, and we will provide a written security questionnaire response, a subprocessor list, and our incident-response commitments to any department that asks. If a formal attestation is a procurement requirement for you, tell us during the demo — we would rather lose the deal honestly than promise a certificate we don't have.
Incident response
If we confirm a breach affecting a department's data, we notify that department's administrators without undue delay, with what we know, what we've done, and what we recommend. Public-records law may apply to the department's own copy of that notice.
Reporting a vulnerability
Email support@onparfireems.com with “security” in the subject line. Good-faith reports are welcome and will never result in action against the reporter. Please do not test against a live department's data — ask us for a sandbox.
Accessibility
We build against WCAG 2.1 AA as our target: keyboard-navigable, screen-reader-labelled controls, visible focus, and contrast checked in both light and dark themes. We do not yet publish a formal VPAT. If your agency requires one for procurement, ask us and we'll tell you honestly where we stand rather than sending a boilerplate.
Buying and paperwork
W-9, vendor packet, certificate of insurance, sole-source justification letter, and a Data Processing Addendum are available on request — email sales@onparfireems.com and we'll send the set the same day.
Get a demo · Privacy Policy · Terms of Service · Acceptable Use Policy · Compare
Whyte Line Holdings LLC dba OnPar Fire & EMS · Texas · Last reviewed 4 August 2026