Security & trust

Real controls. Clear boundaries.

Trust should come from how the product is designed and operated, not from certifications it has not earned.

Discuss security

Controls in the product today

Designed to reduce unnecessary exposure.

These are concrete product controls. OmniSansar does not currently claim SOC 2, HIPAA, ISO 27001, GDPR certification, pen-test results, or an uptime SLA.

01

Separate customer databases

Each customer’s data lives in its own separate database—not a shared table separated only by a tenant column.

02

Encrypted credentials

API keys and channel access tokens are encrypted at rest using AES-256-GCM and are never returned by the API.

03

Verified inbound messages

Inbound channel webhooks are cryptographically signature-verified before they are processed.

04

Authenticated access

Role-based access control is applied and every non-public endpoint is authenticated.

05

Agent audit logs

Agent actions are recorded so teams can review what happened inside the workflow.

06

Human approval gates

Sensitive actions can be configured to require a person’s approval before execution.

Design discipline

Some data should stay outside Omni.

Sensitive-sector templates are deliberately narrower than a generic CRM. That boundary is a product decision, not a missing checkbox.

Healthcare

Front-desk logistics, not clinical data.

Healthcare templates use department, appointment type, and referral source. Clinical fields are deliberately excluded.

Counselling

Session content never enters Omni.

The workflow covers scheduling, attendance, and billing logistics. Session content stays in the practitioner’s clinical system.

Honest boundary

OmniSansar describes the controls it has. It does not claim a certification, compliance status, or assurance report that does not exist.

Bring your security questions

Review the controls and boundaries with our team.

Show us the journey today. We’ll help you connect it into one clear system.

Book an OmniSansar demo