security & trust

Read-only by architecture, not by promise.

Most monitoring tools ask you to trust their settings. OmniCanary is built so the dangerous path doesn't exist until you deliberately create it — and so leaving is as clean as joining.

The two-app model.

Two separate apps

Monitoring uses a read-only app. Fixing uses a different app you may never authorize. They are never combined into one permission grant.

No credential, no code path

An organization that hasn't opted into remediation cannot be written to. There is no flag to flip — the capability doesn't exist.

Tested on every change

Our CI permanently proves that every write operation is refused for read-only organizations — on every code change we ship.

boundaries

What OmniCanary never does.

Read your messages or meetings

Our scopes cover directory and device metadata. The flagship license policy reads usage reports — never content.

Change your org uninvited

Every fix is preview → confirm → execute → verify, behind the separate opt-in app — and lands in the audit log. No unattended automation.

Share or sell your data

Your organization's mirror exists to evaluate the policies you enabled. Service providers run the infrastructure; nobody else sees it.

Keep data after you leave

Offboarding hard-purges your tenant's data from live systems within 30 days, keeping only minimal deletion evidence. Backups age out on schedule.

isolation

Your data, fenced at the database.

Row-level security

Every row carries your tenant's id, and the database itself refuses cross-tenant access — a fence that binds our own code too, and fails closed.

Proven on every push

Cross-tenant isolation tests run in CI on every change, from the first day the schema existed.

PII-disciplined logs

Logs carry entity ids — never names, emails, or configurations. Failed responses are scrubbed before they are stored anywhere.

offboarding

Leaving is a first-class feature.

step 01

Revoke in Control Hub

Your Full Admin removes the authorization in Webex Control Hub — the same place it was granted.

step 02

Access ends in minutes

We destroy our copies of the tokens and watch for Webex's deauthorization signal; access ends within minutes either way.

step 03

Purged in 30 days

Your tenant's data is hard-purged from live systems within 30 days. Only minimal deletion evidence remains.

Under the hood: managed Postgres with professionally-run backups, secrets kept in environment configuration only, and monitoring on every service. Residency specifics are agreed in the pilot paperwork.

See what your org has been trying to tell you.

Pilots are set up personally, with a Webex specialist — not a signup form. Connect read-only, run the first scan, and keep the findings either way.

support@omnicanary.com