← OnPar home
Security & compliance

Built for records that get audited.

Your controlled-substance ledger is evidence. This page is the plain-English version of how we protect it — written so you can hand it to an IT director or a purchasing office without a follow-up call.

Where your data lives

Controlled-substance records specifically

What we do not claim No software is “DEA-approved” or “DEA-certified” — the DEA does not certify recordkeeping products, and any vendor telling you otherwise is wrong. What we do is keep records in the form 21 CFR 1304 expects and make them readily retrievable for an inspection. Compliance remains your department's legal responsibility; OnPar is the tool that makes it defensible.

Subprocessors

The complete list. Each is contractually limited to providing its service to us.

ProviderWhat it doesData it touches
SupabaseDatabase, authentication, file storageAll department records
NetlifyWeb and app hosting, website formsRequests; form submissions
ApplePush-notification deliveryDevice token, notification text
Anthropic, GoogleOne-shot label-scan processingA single camera frame, processed and discarded — not stored
ResendTransactional email (sign-in links, briefings)Name, work email

What we don't do

Certifications — where we honestly stand

We are a young company and we will not imply otherwise. OnPar does not currently hold a SOC 2, ISO 27001, StateRAMP, or FedRAMP attestation. The controls above are real and in production today, and we will provide a written security questionnaire response, a subprocessor list, and our incident-response commitments to any department that asks. If a formal attestation is a procurement requirement for you, tell us during the demo — we would rather lose the deal honestly than promise a certificate we don't have.

Incident response

If we confirm a breach affecting a department's data, we notify that department's administrators without undue delay, with what we know, what we've done, and what we recommend. Public-records law may apply to the department's own copy of that notice.

Reporting a vulnerability

Email support@onparfireems.com with “security” in the subject line. Good-faith reports are welcome and will never result in action against the reporter. Please do not test against a live department's data — ask us for a sandbox.

Accessibility

We build against WCAG 2.1 AA as our target: keyboard-navigable, screen-reader-labelled controls, visible focus, and contrast checked in both light and dark themes. We do not yet publish a formal VPAT. If your agency requires one for procurement, ask us and we'll tell you honestly where we stand rather than sending a boilerplate.

Buying and paperwork

W-9, vendor packet, certificate of insurance, sole-source justification letter, and a Data Processing Addendum are available on request — email sales@onparfireems.com and we'll send the set the same day.

Get a demo · Privacy Policy · Terms of Service · Acceptable Use Policy · Compare

Whyte Line Holdings LLC dba OnPar Fire & EMS · Texas · Last reviewed 4 August 2026