Security & Trust Architecture
Enterprise Defense-in-Depth Specification
1. Multi-Tenant Database Isolation (RLS)
Omni SDR operates with structural multi-tenant isolation. All customer workspaces are partitioned by unique organizational UUIDs and governed by forced PostgreSQL Row-Level Security (RLS) policies. Cross-tenant leakage is physically impossible at the database kernel level.
2. Cryptographic Envelope Encryption
Sensitive credentials, tokens, and OAuth keys are never stored in plaintext:
- All secrets are protected using Google Cloud KMS Envelope Encryption with automated key rotation.
- Only isolated execution worker microservices operating with restricted least-privilege IAM roles possess access to decrypt authorization credentials.
- Web client browsers never communicate directly with upstream model providers or database instances.
3. Zero-Restricted-Scope Regulatory Architecture
Omni SDR intentionally routes inbound mail processing and outbound verification through hardened Cloudflare Workers rather than requesting broad, invasive Google Workspace `gmail.readonly` scopes. This eliminates third-party token vulnerabilities and preserves customer data sovereignty.
4. Immutable Audit Trails & Hold Mechanisms
Every administrative action, message approval, and credit ledger transition is recorded in an immutable, append-only audit log. In the event of deliverability anomalies or security triggers, emergency Hold Breakers immediately halt outbound lanes across organizations, workspaces, or specific mailboxes within milliseconds.
5. Vulnerability Reporting
We actively collaborate with the security research community. If you discover a potential vulnerability, report it immediately to:
Omni SDR Security Response Team
Email: [email protected]
PGP Key available upon request. Responsible disclosures receive prioritized triage.