Skip to content
Security

How your data is held

Regulated firms are judged on what they can evidence. The platform is built so that evidence is a by-product of the work, and so that access to it is provable.

Tenant isolation

Every query is bound to a tenant boundary and enforced at the service layer rather than filtered in the interface. A misconfigured screen cannot leak another tenant record.

Least-privilege access

Permissions are granular and built from global role templates. Claims are carried in the token and refreshed the moment a role changes, so revocation takes effect immediately.

Immutable audit trail

Records are archived rather than overwritten. Officer removals and identity changes commit alongside their audit entry in a single transaction, so the trail cannot diverge from the data.

Data residency

Deployment is region-aware, so records stay inside the jurisdiction that regulates them. Changing a subject jurisdiction records an audit entry; it does not silently move stored documents.

Credential handling

Upstream provider credentials live in the deployment secret manager, never in the repository. The platform rejects sample credentials, non-official hosts and plain HTTP for regulated APIs.

Verified integrations

Provider hosts are validated against their official endpoints, and production and sandbox environments cannot be mixed by misconfiguration.

See Oomero with your own customers

We will take your team through a real onboarding, for a person and a company, using your own risk policy, and show you exactly what is recorded.