Security
What is protected today. What is not formalised yet.
Outbound OS limits access inside a workspace, isolates workspace data and protects stored connection credentials. We do not claim certifications or assessments that are not available.
Implemented controls
Access follows the workspace and the job.
These are product behaviours in use, not a compliance framework or a substitute for one.
- Role-based access
- Admin, manager, agent and viewer roles separate what different users can do in the workspace.
- Lead pools
- Pools limit which leads a user sees, so access can follow team or territory responsibility rather than exposing every lead.
- Workspace isolation
- Data is isolated per workspace. One customer workspace does not share its records with another.
- Activity log
- The product records who sent what, giving managers a history tied to the person who acted.
Connection credentials
Encrypted at rest.
Stored third-party credentials used for connections such as WhatsApp, email and IndiaMART are encrypted at rest with AES-256-GCM.
Formal assurance
Documents and assessments not currently available.
The absence is stated directly so procurement teams know what cannot be supplied today.
SOC 2
Outbound OS does not currently claim SOC 2 certification or provide a SOC 2 report.
Penetration testing
There is no completed third-party penetration-test report available to share.
Data processing agreement
A standard DPA is not currently published.
Named subprocessors
A named subprocessor list is not currently published.
Need a formal answer for your review? Email hello@outboundos.space with “Security question” in the subject.
Report a security issue.
Send the affected area, steps to reproduce and possible impact. Please do not include credentials or unnecessary customer data.