We build Octom with security as part of the product. No online service can promise perfect security, so this page describes what we actually do rather than making guarantees.
Data isolation
Each workspace’s data is separated by access rules enforced in the database itself. A signed-in user can only read and change data that belongs to workspaces they are a member of.
Encrypted connections
Traffic between your browser and Octom uses HTTPS.
Authentication
Sign-in and password handling are provided by Supabase Authentication. Passwords are stored only in hashed form and are never visible to us.
Server-side checks
Actions with side effects, such as billing, the AI assistant and account deletion, are checked on the server for an authenticated user. The AI assistant and the contact form have usage limits to reduce abuse.
Payments
Card details are entered on Stripe’s pages. Octom never receives or stores them.
Report a problem
If you believe you found a security issue, please tell us through the contact form with enough detail to reproduce it, and give us reasonable time to fix it before sharing it publicly.