Security
Last updated September 28, 2026
You trust OmniLead with your pipeline, your mailboxes and your contacts. Here's how we protect them.
Workspace isolation
Every table that holds workspace data carries a workspace_id and has Postgres row-level security enabled. Policies check membership through a single security-definer function, so a query can only ever see rows from workspaces you belong to, even if application code has a bug. Automated tests prove that one workspace can't read or write another's data.
Encryption
- All traffic uses TLS. We send HSTS and redirect HTTP to HTTPS.
- Mailbox passwords and OAuth tokens are encrypted at the application layer with AES-256-GCM before they reach the database. Keys are versioned so they can be rotated without downtime.
- Data at rest is encrypted by our database and storage provider.
- API keys are stored as hashes. We show a key once, when you create it.
Access and audit logs
- Roles (owner, admin, member) control who can manage billing, members, mailboxes and exports.
- The audit log records every reveal, export, billing change, mailbox connection, member change, data export and deletion, with who did it and when.
- Staff access to production is limited to the people who need it, and administrative actions are logged.
Application security
- Every server entry point validates input with a schema before it touches data.
- Rate limits protect sign-in, the public API and free tools.
- A strict Content Security Policy and security headers are set on every response.
- Webhooks from Stripe are signature-verified and processed idempotently.
- Dependencies are pinned and checked in continuous integration.
Infrastructure
OmniLead runs on Netlify and Supabase, with the database hosted in the EU. Background jobs are idempotent and retried with a maximum attempt count, so a failure can't double-charge credits or double-send email. See our sub-processors.
Email safety
Your mailboxes are protected by the same controls that protect your recipients: daily caps, sending windows, gradual ramp-up, a circuit breaker that pauses campaigns at a 5% bounce rate, one-click unsubscribe, and suppression that applies across your workspace.
Responsible disclosure
If you find a vulnerability, email security@omni.cloudgens.net with the steps to reproduce it. Our contact details are also published in security.txt. We'll acknowledge your report within 3 business days and keep you updated until it's fixed.
Please:
- Test only against your own account and workspace. Don't access, change or delete other people's data.
- Don't run denial-of-service tests, spam, social engineering or physical attacks.
- Give us reasonable time to fix the issue before you disclose it publicly.
We won't take legal action against good-faith research that follows these rules, and we're happy to credit you when the fix ships.