Private launch preparation is underway · briefings and launch-list registration are open.
security & trust

Read-only by architecture, not by promise.

Assurance monitors over an app that holds no write permission at all. Actions and Studio run under separate authorizations you grant knowingly, per product — and everything leaves an audit record.

Your Webex organization — rooms, devices and people — read over one read-only connection by OmniCanary outside the boundary; Actions and Studio connect only under separate authorizations your Webex organization read-only OmniCanary Actions separate authorization Studio separate authorization

Join the launch list

Product and availability updates. Not a stream of marketing email.

double opt-in: we send a confirmation email first, unsubscribe any time

By joining you consent to receiving launch and availability updates by email. We store your address, the dates you joined and confirmed, and the version of our privacy notice in force at the time. We store nothing else, and never your name or employer. You can withdraw at any time with the unsubscribe link in any email. See the privacy notice for the full detail.

Permissions, per product.

Assurance — read-only, structurally

Monitoring runs on an app that reads only the Webex operational data required for the checks you use. It holds no write permission — not a setting, a structural boundary.

Actions — separately authorized

Guided fixes use their own connection, authorized separately by a Webex administrator. Every fix follows preview, named approval, apply, verify — and lands in the audit trail.

Studio — permissions per builder

Workflows, macros, and bots state their permissions before an administrator enables them, and run only within rules an authorized administrator has reviewed and published.

boundaries

Data and access boundaries.

Boundary What it means
No content access in Assurance Assurance never requests access to Webex messages, recordings, transcripts, files, or meeting content. Optional products state their additional permissions before an administrator enables them — a bot you build processes only the messages and commands directed to it, in the spaces where it is installed.
No hidden changes Guided fixes require a named approval. Automations run only after an authorized administrator publishes their explicit rules, within the scopes those rules were granted. Both leave an audit record.
No selling of customer data We do not sell customer data. Approved subprocessors handle only the data needed to provide hosting, monitoring, and email services.
No data kept after offboarding Live tenant data is deleted within the contracted period after offboarding. Backup copies expire under the published backup-retention schedule, and minimal deletion evidence is retained for the stated period.
isolation

Your data lives in its own isolated space.

Isolated by design

Every customer’s data lives in its own isolated space — a request without your organization’s context sees nothing.

Verified before every release

Isolation and read-only boundaries are verified automatically before every release — not checked once and assumed.

Logs minimize personal data

Operational logs minimize personal data. Names, email addresses, configurations, and credentials are excluded or scrubbed.

what enterprises expect

The paperwork and the controls.

Control What it means
DPA and subprocessor list A data processing agreement and the subprocessor list are part of onboarding — in place before any customer organization is connected.
Role-based portal access Portal access follows roles: who can view findings, who can approve fixes, who can publish automations. Approvals always carry a name.
Audit trail on every change Every guided fix, workflow run, macro deployment, and bot response is recorded: what changed, who approved it or which published rule allowed it, and when.
Disconnect any time Remove the authorization in Control Hub and access ends. Deletion follows the published timelines — see how offboarding works below.
offboarding

How offboarding works.

step 01

Revoke in Control Hub

A Webex administrator removes the authorization in Control Hub — the same place it was granted.

step 02

Access ends

OmniCanary marks the connection inactive, discards stored token material, and stops scheduled access. Webex deauthorization can take a few minutes to propagate.

step 03

Data is deleted

Live tenant data is deleted within the contracted period. Backup copies expire under the published backup schedule; minimal deletion evidence is retained as described in the retention notice.

OmniCanary is hosted in the European Union (Amsterdam) on managed, encrypted infrastructure — encrypted in transit and at rest, TLS-only at the public edge. Before customer onboarding we publish a backup retention schedule and an incident contact.

Build a calmer Webex operation.

Tell us about your Webex environment and the work you want to improve. Onboarding opens in scheduled waves. Join the launch list for availability updates.

support@omnicanary.com