OpenBOM security is a layered model combining AWS infrastructure, SOC 2 Type II certified operational controls, AES-256 encryption at rest and in transit, granular per-object sharing permissions, MFA support and optional enterprise Single Sign-On using WorkOS enterprise platform that delegates authentication to the customer’s own identity provider. OpenBOM employees cannot access customer data unless it is explicitly shared with the support group.
Every few weeks, the same moment repeats itself in an onboarding call. We are halfway through setting up a first catalog, the engineer is happy, the BOM is coming together, and then someone who has been quiet the whole time unmutes and says: “Before we go further, I need to send this to our IT group. What do they need to know?”
That question is not an obstacle. It is the most reasonable thing anyone says on those calls. Product data is the most valuable information a manufacturing company owns. Drawings, part numbers, supplier pricing, and the assembly structure of a machine you spent three years developing are not files you hand to a cloud vendor casually. After 25+ years in this industry, I have watched engineering teams get burned by systems nobody could explain, and I understand exactly why the IT organization wants answers before anyone imports a single item.
So this article is a refresher. Not a marketing page, and not a certificate you frame on the wall, but a plain description of how OpenBOM protects your data, written so you can forward it to the person who asked. The full reference lives on our OpenBOM Security page, and we have just published a new Single Sign-On configuration guide for IT teams who want the authentication details in depth.
Cloud Is Not A Security Compromise, It Is A Security Upgrade
The oldest objection to cloud PLM is that data feels safer on a server you can walk over and touch. I understand the instinct. I also know what those servers usually look like in practice: a machine under a desk in the engineering office, patched when someone remembers, backed up to a drive that nobody has tested restoring in two years, accessible to anyone who knows the shared password.
OpenBOM runs on AWS infrastructure, using EC2 and Virtual Private Cloud isolation for network traffic in and out of the service. That means physically secured, globally distributed data centers with redundant power, cooling, and networking, operating under certifications including ISO 9001, ISO 27001, SOC 2 Type II, FIPS 140-2, and NIST 800-53. No small or mid-size manufacturer is going to reproduce that in a server closet, and none of them should try. The question was never cloud versus secure. It was who is better resourced to run infrastructure, and the honest answer for almost every engineering team is: not you, and that is fine.
SOC 2 Type II Is What “Prove It” Looks Like In Practice
Anyone can say their platform is secure. SOC 2 Type II is what happens when a third party checks.
SOC 2 is a framework from the American Institute of Certified Public Accountants that evaluates security, availability, processing integrity, confidentiality, and privacy in a cloud service. The distinction that matters is between Type I and Type II. A Type I report examines whether your controls are designed correctly at a point in time. A Type II report examines whether those controls actually operated effectively over a sustained period, usually twelve months. It is the difference between showing an auditor your fire extinguishers and proving you inspected them every month for a year.
OpenBOM has achieved SOC 2 Type II compliance in accordance with AICPA standards for SOC for Service Organizations, also known as SSAE 18, with an unqualified opinion. If your IT organization wants the report itself, they can have it. Contact support@openbom.com with SECURITY in the subject line. An NDA is required, which is standard practice for these reports across the industry.
Encryption Is Table Stakes, So Here Is Exactly What We Encrypt
I am always a little suspicious when a vendor leads with encryption, because encryption is the minimum, not the differentiator. Still, IT questionnaires ask, so here is the specific answer.
All communication between OpenBOM servers, web browsers, and client applications including the CAD add-ins uses HTTPS with TLS. All data stored in OpenBOM databases and AWS file storage is encrypted with AES-256. Encryption applies both at rest and in transit, which means your data is protected from the moment it leaves your workstation through to where it sits on disk. There is no gap in the middle where a CAD file travels in the clear.
Your Sharing Model Is The Real Security Perimeter
Here is the part that most security conversations underweight. Infrastructure certifications tell you the walls are strong. They tell you nothing about who you handed keys to.
In OpenBOM, sharing is the foundation of the security model. Every catalog, item, and BOM is governed by explicit permissions, and those permissions are granular rather than binary. A user can have no access, read-only access, access through a user-defined view that exposes only selected properties, edit rights, or admin rights. The user-defined view level is the one teams tend to discover late and then use constantly, because it is how you share a BOM with a contract manufacturer without exposing your cost columns.
Now the honest part, and I would rather say it here than have someone discover it later. Any user who can read data can export it, either through the export command or by copying from the browser. OpenBOM cannot prevent that, and no system in this category truly can. Once data has been exported, it is outside our security control and inside yours. This is exactly why the sharing model deserves more of your attention than the certification list, and why we recommend strong passwords, multi-factor authentication, and never sharing credentials between people in your company.
OpenBOM Employees Cannot See Your Data Until You Share It With Us
This one comes up in almost every enterprise review, so let me be direct about it. OpenBOM employees have no ability to access customer data. When you need support on a specific BOM, you share it with the support group using the same Share command you would use for a colleague, and that access exists because you granted it.
Our operations personnel reach the server environment only through a dedicated authentication mechanism with secured credentials and two-factor authentication. Support access and infrastructure access are separate things, and neither is a back door into your catalogs.
Your Credit Card Never Touches An OpenBOM Server
A small point that saves time in procurement reviews. OpenBOM uses Stripe as a third-party payment processor. Credit card information is encrypted in your browser or mobile client and sent directly to Stripe. We do not store card data on OpenBOM servers, and the payment process is PCI compliant. If your finance organization has questions about payment handling specifically, Stripe is the right party to ask.
Single Sign-On Puts Your IT Organization Back In Control
Recent updates to the platform security is our migration to WorkOS infrastructure – a leading enterprise security platform.
SSO changes who governs access to OpenBOM. Instead of your engineers maintaining a separate OpenBOM password, authentication is delegated to your corporate identity provider,. Your MFA policy, your conditional access rules, your device compliance requirements, and most importantly your offboarding process all apply to OpenBOM automatically, because your identity provider is doing the authenticating.
Two design decisions in our implementation matter for security review. First, OpenBOM never sees or stores corporate passwords, because authentication happens entirely inside your identity provider. Second, membership stays invite-only: just-in-time provisioning is disabled by default, so a successful authentication alone never creates an account or grants access to your company data. Your OpenBOM administrator decides who is in the organization, independently of what your directory contains.
We have published the full architecture, the supported identity providers, the setup sequence, and a set of answers written specifically for vendor risk questionnaires on the OpenBOM SSO documentation page. If you are the person who was asked “what does IT need to know,” that page is the thing to forward.
If You Find A Problem, Tell Us And We Will Move
No platform is free of bugs, and pretending otherwise is its own security risk. If you believe you have found a security issue in OpenBOM, contact support@openbom.com with SECURITY in the subject line. We investigate reported issues quickly and respond as fast as we can. We ask only that you give us the chance to address the issue before disclosing it publicly.
What To Do With This
If you are evaluating OpenBOM, three links cover almost everything your organization will ask for. The Security page is the complete reference on infrastructure, certifications, encryption, and data protection. The SSO documentation covers authentication architecture and setup for your IT team. The Privacy page covers how we handle personal information.
And if you have a question none of them answer, email support@openbom.com with SECURITY in the subject line. Real people read it, and a security question from a prospect has never once annoyed us. It usually means you are the kind of customer who takes their own product data seriously, which is the kind we want.
REGISTER FOR FREE to check how OpenBOM can help.
Best, Oleg
FAQ
Is OpenBOM SOC 2 certified?
Yes. OpenBOM has achieved SOC 2 Type II compliance under AICPA standards for SOC for Service Organizations (SSAE 18) with an unqualified opinion. A copy of the report is available from support@openbom.com under NDA.
Where is OpenBOM data stored and how is it protected?
OpenBOM runs on AWS infrastructure using EC2 and Virtual Private Cloud isolation. All data in databases and AWS file storage is encrypted with AES-256, and all communication uses HTTPS with TLS, so data is encrypted both at rest and in transit.
Can OpenBOM employees see my product data?
No. OpenBOM employees have no ability to access customer data until it is explicitly shared with the support group using the Share command. Operations personnel access the server environment only through a dedicated authentication mechanism with two-factor authentication.
How does OpenBOM control who can see a BOM?
Through a granular sharing model applied per object. Access levels are no access, read-only, access through a user-defined view that exposes only selected properties, edit, and admin.
Can users export data out of OpenBOM?
Yes. Any user with read access can export data or copy it from the browser, and once exported it is outside OpenBOM’s security control. This is why the sharing model, strong passwords, and multi-factor authentication matter more than any single certification.
Does OpenBOM support Single Sign-On?
Yes. OpenBOM supports SSO and usesWorkOS Enterprise Platform infrastructure.More information on the dedicated SSO page documentation.
Does OpenBOM store credit card information?
No. Payments are processed by Stripe, a third-party PCI compliant payment processor. Card data is encrypted in the browser and sent directly to Stripe, never stored on OpenBOM servers.
How do I report a security issue in OpenBOM?
Email support@openbom.com with SECURITY in the subject line. OpenBOM investigates reported issues quickly and asks that issues not be disclosed publicly until they have been addressed.
Join our newsletter to receive a weekly portion of news, articles, and tips about OpenBOM and our community.