ODAU
Security and data handling

We govern systems, not people.

Odau uses only customer-authorized business data needed to provide the service. It does not monitor employees, and your data is never sold.

Scope of access

What customers control, and what we never touch.

What customers control
Which business data is authorized Which permissions are granted Who can access the service When access is revoked
What Odau will never read
Browsing history or pages visited Screens, keystrokes or session recordings Messages, documents or file contents Anything that turns a colleague into a metric
Our safeguards

Four rules we do not bend.

Least privilege, read-only
We ask for the narrowest scope needed to provide the service, and use read-only access wherever read-only is possible.
No browser extension
Nothing is installed on your employees’ machines. No part of Odau depends on watching a browser.
Defensible answers
Your team can review important answers and the decisions made from them without relying on a black box.
Evidence, not surveillance
Approvals, access reviews, ownership changes and remediation are recorded as governance evidence — actions taken on systems, not observations of people.
Where we are today

Honest about what is in place.

Encryption
Customer-authorized business data is encrypted in transit and at rest.
Access control
Access is permissioned, reviewable and limited to authorized users.
Certifications
SOC 2 readiness is underway. We will not claim a certification before it is issued — ask for current status and we will tell you plainly.
A tool with no owner is a governance problem. An employee with a browser is not.

Send this to your security team.

We answer a review questionnaire before you commit to anything.Including where we are not ready yet.

Ask for current status