Separate customer databases
Each customer’s data lives in its own separate database—not a shared table separated only by a tenant column.
Security & trust
Trust should come from how the product is designed and operated, not from certifications it has not earned.
Discuss securityControls in the product today
These are concrete product controls. OmniSansar does not currently claim SOC 2, HIPAA, ISO 27001, GDPR certification, pen-test results, or an uptime SLA.
Each customer’s data lives in its own separate database—not a shared table separated only by a tenant column.
API keys and channel access tokens are encrypted at rest using AES-256-GCM and are never returned by the API.
Inbound channel webhooks are cryptographically signature-verified before they are processed.
Role-based access control is applied and every non-public endpoint is authenticated.
Agent actions are recorded so teams can review what happened inside the workflow.
Sensitive actions can be configured to require a person’s approval before execution.
Design discipline
Sensitive-sector templates are deliberately narrower than a generic CRM. That boundary is a product decision, not a missing checkbox.
Healthcare templates use department, appointment type, and referral source. Clinical fields are deliberately excluded.
The workflow covers scheduling, attendance, and billing logistics. Session content stays in the practitioner’s clinical system.
OmniSansar describes the controls it has. It does not claim a certification, compliance status, or assurance report that does not exist.
Bring your security questions
Show us the journey today. We’ll help you connect it into one clear system.
Book an OmniSansar demo