Skip to content
OmniLeadDocs
Sign in

How OmniLead keeps your data secure

Workspace isolation, encryption of mailbox secrets, the audit log, sign-in security and how to report a vulnerability.

4 min readLast updated

OmniLead holds two kinds of sensitive data for you: your CRM, and the credentials for the mailboxes you send from. This article explains how both are protected, what the audit log records, and how to keep your own account secure.

Workspace isolation

Every row of customer data in OmniLead, from leads and notes to messages and credits, carries the ID of the workspace it belongs to. The database enforces Row Level Security on every one of those tables: a query only returns rows from workspaces you're a member of, however it's written. The check happens inside Postgres, not only in application code, so a bug in one screen can't expose another customer's data.

We test this directly. Our automated tests sign in as a member of one workspace and try to read and write another workspace's data through the same public API key the app uses. Every attempt must fail before a release ships.

Encryption

  • In transit: every connection to OmniLead uses HTTPS (TLS 1.2 or later). Connections from OmniLead to your mail server use TLS on ports 465, 587 and 993.
  • At rest: the database and file storage are encrypted at rest by our hosting provider.
  • Mailbox secrets: SMTP and IMAP passwords, app passwords and OAuth tokens are encrypted again, field by field, with AES-256-GCM before they're stored. Each value has its own random nonce and an authentication tag, so tampering is detected. Keys are versioned, which lets us rotate them without downtime. Secrets are decrypted only in memory, at the moment a mailbox connects to send or sync, and are never shown back to you or included in exports and logs.
  • API keys: OmniLead stores only a SHA-256 hash of each key. The full key is shown once when you create it. If you lose it, revoke it and create a new one.
  • Passwords: account passwords are handled by our authentication provider and stored as salted hashes. OmniLead never sees them in plain text after sign-in.

Audit log

The audit log is a permanent record of sensitive actions in your workspace. Owners and admins can read it in Settings → Workspace → Audit log. Each entry shows who did what, when, and from which IP address.

It records:

  • Reveals: every contact revealed, by whom, and the credits charged or refunded.
  • Exports: every CSV or JSON export and data-request download, with the filter used and the row count.
  • Billing: plan changes, checkouts, credit pack purchases, refunds, trial expiry and cancellations.
  • Mailboxes: mailboxes connected, disconnected or reconnected.
  • Members: invitations sent, accepted and revoked, role changes and removals.
  • API: API keys created and revoked, and webhook endpoints added or deleted.
  • Compliance: changes to the postal address and country rules, suppressions removed, and data requests completed.
  • Deletions: leads, lists and workspaces deleted.

Audit entries can't be edited or deleted by anyone in the workspace, including owners.

Sign-in security

You can sign in with email and password, a magic link, or Google.

Other protections:

  • Sign-in and password-reset attempts are rate-limited.
  • Email sign-ups must verify their address before they can use the app.
  • Signups from disposable email domains are blocked.

If you think someone else has used your account, reset your password, revoke your API keys in Settings → API, check the audit log, and contact support so we can end every active session.

Infrastructure

OmniLead runs on Supabase (Postgres database, authentication and file storage, hosted in the EU) and Netlify (web application and background jobs). Payments are processed by Stripe; OmniLead never sees or stores card numbers. The full list of sub-processors, with what each one handles, is at /legal/subprocessors.

The web app sends strict security headers, including a Content Security Policy, HSTS and frame protection, and every form and API input is validated on the server.

Responsible disclosure

If you find a security vulnerability, please tell us before telling anyone else.

  1. Write it up

    Describe the issue, the steps to reproduce it and its impact. Include URLs, request and response samples, and screenshots if they help.

  2. Send it privately

    Email security@omni.cloudgens.net. Our contact details are also in /.well-known/security.txt.

  3. Give us time to fix it

    We reply within three business days, keep you updated, and credit you when the fix ships if you'd like.

Please test only against your own account and workspace, don't access or change other customers' data, and don't run denial-of-service or social-engineering tests. We won't take legal action against research done in good faith within these limits.

Can OmniLead staff see my data?

Only when needed to operate the service or when you ask for support, and every administrative action is logged. Support won't read your mailbox contents unless you ask us to investigate a specific conversation.

Do you sign a DPA?

Yes. Our Data Processing Agreement is at /legal/dpa and applies to every customer automatically.

Where is my data stored?

The database and file storage are hosted in the EU (Frankfurt). Email you send goes through your own mail provider.

What's next