Security & responsible disclosure.
Onam Security responsible disclosure policy, security practices, and vulnerability reporting. We take security seriously and respond within 24 hours.
This page is maintained by Onam Security. Last updated: July 2026.
How we protect your data
These are the controls currently enabled in Onam's production environment. This page is app-owner content and not an independent certification.
Encryption at rest
AES-256 for all finding data, configuration snapshots, and credential metadata. Per-tenant encryption keys managed in an HSM-backed key vault.
Encryption in transit
TLS 1.2 minimum, TLS 1.3 preferred, for every request from browser, API, and cloud-connector traffic.
Read-only credentials
Onam never writes, deletes, or modifies your cloud resources. Onboarding uses read-only IAM roles or service principals — no destructive permissions.
No credential storage
We store role ARNs, service-account IDs, and workload-identity federation trust configuration — never static access keys or passwords.
Penetration testing
Annual third-party penetration test by an independent CREST-affiliated firm. Executive summary is available on request under NDA.
Report a vulnerability
If you believe you've discovered a vulnerability in Onam's platform or website, we want to hear from you. Report it to security@onam.security with steps to reproduce, affected endpoints, and any relevant proof-of-concept material.
A human confirms receipt of your report.
Severity assessed and validated.
You are kept in the loop until closure.
Safe harbour
Onam will not pursue legal action against researchers who act in good faith to identify and report vulnerabilities, provided they: avoid privacy violations, service degradation, and data destruction; do not access or modify data that does not belong to them beyond what is necessary to demonstrate the vulnerability; give us a reasonable opportunity to remediate before public disclosure; and stop testing and report immediately if they encounter sensitive data.
Out of scope
Reports of missing best-practice headers without a demonstrable impact, self-XSS, social engineering, physical attacks, and any activity that violates the safe-harbour conditions above.
PGP key available on request. Please do not include exploit payloads that would trigger production alerts before we've had a chance to acknowledge your report.