Security is a shared responsibility. Ommicom applies technical and operational safeguards appropriate to risk. Customers are responsible for credentials, Workspace permissions, and timely reporting of suspicious activity.
Encryption and secure connections
- Production traffic is protected using TLS/HTTPS.
- Sensitive authentication data is protected and is not displayed again as plain text.
Access control and permissions
- Workspace roles restrict access according to responsibility.
- Customers should review members and revoke access promptly when roles change.
Workspace data isolation
- Access is scoped to the authorized Workspace and user.
- Application requests validate Workspace context to prevent unauthorized cross-tenant access.
Logging and monitoring
- Operational and security events are recorded for troubleshooting, audits, and threat detection.
- Monitoring is limited to legitimate security and operational purposes.
Backup and recovery
- Ommicom maintains backup and recovery procedures appropriate to its infrastructure and service plans.
- Customers should also export critical business data according to their own requirements.
Incident response
- We prioritize containment, investigation, recovery, and prevention when an incident occurs.
- Affected parties are notified according to severity and applicable law.
Vendors and third-party integrations
- Integrations use provider-defined authentication, APIs, and permission scopes.
- Customers should disconnect integrations that are no longer in use.
Responsible disclosure
- Report a vulnerability with reproduction steps and impact to security@ommicom.com.
- Do not access other users’ data, disrupt services, or publish details before a reasonable remediation period.
Report a security issue
Send technical details and your contact information to
security@ommicom.com