Security & Incident Policy
Odenaro uses layered safeguards designed for a multi-tenant SaaS environment.
Core controls
Controls include authenticated access, role-based restrictions, tenant data separation, CSRF protections, session controls, security headers, backups, error logging and critical-action audit logging.
Access to sensitive data
Access is limited by role and product workflow. Customers are responsible for assigning appropriate users and removing access when no longer needed.
Incident response
Security incidents are assessed, contained, logged and investigated. Where a confirmed personal-data breach affects customer workspace data, the affected customer is informed without undue delay with available facts needed for its regulatory assessment.
Customer responsibilities
Customers must use strong credentials, restrict account sharing, review user access, keep endpoint devices secure and promptly report suspected compromise.
Questions: info@odenaro.com