Trust
Security at Oleon
How the product protects the conversations a business runs through it, what it is certified for, and where to send a vulnerability report.
Encrypted on the wire and at rest.
Conversation content, attachments and any credentials you store with us are encrypted, in transit and where they sit.
The message
Has my August instalment been received?
What is stored
Message content, attachments and stored credentials are held as ciphertext rather than as readable text.Three ways to prove it is you.
Available on every account, not held back for a plan. Sensitive changes ask you to confirm again before they are applied.
Access is granted per place.
Every grant names an organization or a project and the level it carries, so what somebody can open is decided where they were added rather than globally. Removing access takes effect immediately across open sessions.
Every change is written down, and you can read it.
Who made it, what changed and whether it succeeded. The trail is in the product, filterable, and open to you rather than only to us.
It is your data, and it leaves when you want.
Export conversations, message history and project contacts on demand or on a schedule you set once. Your conversations are never sold, and no provider we work with may train a model on them.
Built on certified infrastructure.
The product runs on established managed providers under contract, processing data on our instruction only. We name every provider in writing on request.
Held by the providers we build on
Compliance and privacy
What we are held to, what we are certified for, and what we will send you in writing.
- Data protection
- Sri Lanka's Personal Data Protection Act No. 9 of 2022 frames what we owe you. The privacy policy sets out which data we answer for as controller and which we hold on your instruction as processor.
- Certified infrastructure
- The hosting, database and storage platforms the product is built on are operated by providers holding SOC 2 Type II and ISO 27001 certification, covering the infrastructure your data sits on. We confirm the current providers and the scope of their certifications in writing for a review.
- Security reviews
- We answer security questionnaires in writing and provide the full list of providers that process data on our behalf. Write to us and ask.
- Incidents
- If a breach affects your data we will tell you what we know, while it is still awkward rather than once it is tidy.
- Service status
- Availability, incidents and maintenance are published as they happen on the status page.
Reporting a vulnerability
If you have found something, this is where it goes and what happens next.
Send what you found, where you found it, and enough detail to reproduce it to security@olee.ai. We reply within three working days, tell you whether we can confirm it, and tell you what we are doing about it. If you want the credit, you get the credit.
- Testing in good faith
- Stay inside an account you own, take only what you need to prove the point, do not touch anyone else's data, and tell us before you tell anyone else. Do that and we will not pursue you.
- Out of scope
- Denial of service, anything that degrades the service for other customers, social engineering of our staff or customers, physical attacks, and the raw output of an automated scanner with nothing demonstrated.
- Not a security report
- A lost password, a suspicious message or an account you think has been taken over is support, and support is faster. Those go to the addresses in the privacy policy.
Contact
Questions about how your data is held, where it goes and what we do with it. For a security review or a procurement questionnaire, say so and we will answer it in writing and send the full provider list.
Oleon