Outbound OS

Security

What is protected today. What is not formalised yet.

Outbound OS limits access inside a workspace, isolates workspace data and protects stored connection credentials. We do not claim certifications or assessments that are not available.

Implemented controls

Access follows the workspace and the job.

These are product behaviours in use, not a compliance framework or a substitute for one.

Role-based access
Admin, manager, agent and viewer roles separate what different users can do in the workspace.
Lead pools
Pools limit which leads a user sees, so access can follow team or territory responsibility rather than exposing every lead.
Workspace isolation
Data is isolated per workspace. One customer workspace does not share its records with another.
Activity log
The product records who sent what, giving managers a history tied to the person who acted.

Connection credentials

Encrypted at rest.

Stored third-party credentials used for connections such as WhatsApp, email and IndiaMART are encrypted at rest with AES-256-GCM.

Formal assurance

Documents and assessments not currently available.

The absence is stated directly so procurement teams know what cannot be supplied today.

Not available

SOC 2

Outbound OS does not currently claim SOC 2 certification or provide a SOC 2 report.

Not available

Penetration testing

There is no completed third-party penetration-test report available to share.

Not published

Data processing agreement

A standard DPA is not currently published.

Not published

Named subprocessors

A named subprocessor list is not currently published.

Need a formal answer for your review? Email hello@outboundos.space with “Security question” in the subject.

Report a security issue.

Send the affected area, steps to reproduce and possible impact. Please do not include credentials or unnecessary customer data.

Email a disclosure