# Security & Compliance

Cloud encryption, controlled app access, and open-source components help protect the work you entrust to OOMOL.

## Certifications & Compliance

Personal data protection is part of how we build and operate OOMOL.

OOMOL has passed TAC Security’s CASA/ESOF security assessment.

OOMOL follows the personal data protection requirements of the General Data Protection Regulation (GDPR). Our privacy policy explains data processing, your rights, and how to submit a privacy request.

[Read the Privacy Policy](https://oomol.com/privacy/)

## Cloud Data Encryption

OOMOL uses envelope encryption to protect sensitive data in the cloud, with separate layers for encrypting data and protecting encryption keys.

### Encrypt the Data

A data encryption key encrypts the data into ciphertext.

### Protect the Key

A separate key encrypts the data encryption key, forming the two layers of envelope encryption.

## Control App Access

Administrators connect business accounts and define available operations. OOMOL calls apps within the authorized scope, so members do not need to handle account passwords or raw tokens.

[Explore Permissions & Data Access](https://oomol.com/docs/access-control/)

## Open Source for Developer Review

We maintain OpenConnector and make OO-CLI and Connector SDK source code available for developers to inspect, review, and improve.

OpenConnector uses the Apache 2.0 license. The current public OO-CLI and Connector SDK repositories use the MIT license.

### OpenConnector

An authorization gateway for AI agents, maintained by the OOMOL team, that connects business apps and checks access for tool calls.

[View Source Code](https://github.com/oomol-lab/open-connector)

### OO-CLI

Our open-source client-side CLI lets developers inspect the code that runs on their devices.

[View Source Code](https://github.com/oomol-lab/oo-cli)

### Connector SDK

Our open-source connector development SDK lets developers review connector implementations and contribute improvements.

[View Source Code](https://github.com/oomol-lab/connector-sdk)

## Discuss Your Security Requirements

Contact us about security requirements, compliance materials, or a potential vulnerability. Avoid including passwords, tokens, or personal data in your first message.

[Contact the Team](mailto:support@oomol.com)

