Security

Security & responsible disclosure.

Onam Security responsible disclosure policy, security practices, and vulnerability reporting. We take security seriously and respond within 24 hours.

This page is maintained by Onam Security. Last updated: July 2026.

Practices

How we protect your data

These are the controls currently enabled in Onam's production environment. This page is app-owner content and not an independent certification.

Encryption at rest

AES-256 for all finding data, configuration snapshots, and credential metadata. Per-tenant encryption keys managed in an HSM-backed key vault.

Encryption in transit

TLS 1.2 minimum, TLS 1.3 preferred, for every request from browser, API, and cloud-connector traffic.

Read-only credentials

Onam never writes, deletes, or modifies your cloud resources. Onboarding uses read-only IAM roles or service principals — no destructive permissions.

No credential storage

We store role ARNs, service-account IDs, and workload-identity federation trust configuration — never static access keys or passwords.

Penetration testing

Annual third-party penetration test by an independent CREST-affiliated firm. Executive summary is available on request under NDA.

Responsible disclosure

Report a vulnerability

If you believe you've discovered a vulnerability in Onam's platform or website, we want to hear from you. Report it to security@onam.security with steps to reproduce, affected endpoints, and any relevant proof-of-concept material.

Acknowledgement
Within 24 hours

A human confirms receipt of your report.

Initial triage
Within 5 business days

Severity assessed and validated.

Remediation
Prioritised by severity

You are kept in the loop until closure.

Safe harbour

Onam will not pursue legal action against researchers who act in good faith to identify and report vulnerabilities, provided they: avoid privacy violations, service degradation, and data destruction; do not access or modify data that does not belong to them beyond what is necessary to demonstrate the vulnerability; give us a reasonable opportunity to remediate before public disclosure; and stop testing and report immediately if they encounter sensitive data.

Out of scope

Reports of missing best-practice headers without a demonstrable impact, self-XSS, social engineering, physical attacks, and any activity that violates the safe-harbour conditions above.

security@onam.security

PGP key available on request. Please do not include exploit payloads that would trigger production alerts before we've had a chance to acknowledge your report.