Skip to main content
Odella uses a layered security model for identity, customer separation, worker execution, connected applications, model access, and human approval. Product controls and customer configuration work together: Odella operates the platform controls, while each customer decides who may access its account and what each worker is permitted to use.
This page is a non-contractual product overview. The Terms of Use, Privacy Policy, Data Processing Addendum, and applicable order form or written agreement govern where they apply.

Security model

Identity and access

Authenticated users operate within an organization account. Administrative and resource permissions determine what each user can configure or access.

Customer and worker boundaries

Customer context and worker assignments are used to limit access to workflows, knowledge, templates, applications, and tools.

Controlled execution

AI Employees perform work in isolated execution environments with bounded resources and scoped platform access.

Capability enforcement

Tools and integrations are made available through controlled platform capabilities rather than unrestricted access to external systems.

Protected credentials

Integration and model-provider credentials are managed by platform services and are not intentionally exposed to worker workspaces.

Human oversight

Approval policies and workflow review steps keep people in control of sensitive, external, and high-impact actions.

Identity and least privilege

Access decisions can involve several layers:
  1. The authenticated organization and user
  2. The selected AI Employee
  3. Resources assigned to that worker
  4. The current conversation, workflow, or task
  5. Tool-specific allow, block, and approval rules
  6. The connected account’s own permissions
A valid user session or active worker does not grant access to every organization resource. Assign workers only the capabilities required for their responsibilities and remove access when it is no longer needed.
Odella security settings
See Security & Privacy settings for inbound access, outbound messaging, tool approval policies, and saved exceptions.

Data protection

The technical and organizational measures described in the DPA include, as applicable:
  • Role-based and least-privilege access
  • Unique identities and multi-factor authentication for privileged and critical production access
  • Access logging and periodic access review
  • Encryption in transit using TLS 1.2 or higher
  • Encryption at rest using AES-256 or equivalent provider-managed encryption
  • Managed secret storage and access restrictions
  • Logical customer-separation controls
  • Development and production separation
  • Change review, testing, deployment records, and recovery practices
  • Vulnerability, dependency, and cloud-security monitoring
  • Security logging, incident response, backup, and recovery procedures
  • Vendor and Subprocessor review
  • Documented deletion and disposal procedures
The complete and current contractual description is in Annex II of the DPA.

AI Employee execution

Worker execution is separated from the public application tier. Persistent customer work and replaceable execution capacity are treated separately, and tool availability is resolved from the worker’s authorized resources and policies. Important customer controls include:
  • Worker role and manager
  • Assigned skills, workflows, templates, and knowledge
  • Connected inboxes and applications
  • Working hours and service state
  • Inbound and outbound messaging policies
  • Tool approval policy and saved tool rules
  • Human approval steps inside workflows
See AI Employee settings for the complete configuration reference.

Integrations and credentials

Odella supports OAuth and other appropriate authentication methods for customer-authorized applications. Connection and authorization are completed through controlled application flows, and protected credentials are associated with the relevant account or user scope. Workers normally use connected applications through authorized tools. They do not need reusable application credentials in their workspace. A connected application remains subject to:
  • The provider’s permissions and terms
  • Organization and user scope
  • Worker assignment
  • Tool approval rules
  • Outbound-recipient policy
  • Workflow approval steps
Custom integrations connect customer-selected remote MCP servers and carry additional third-party risk. See Custom integrations for endpoint requirements, authentication, assignment, and the conservative tool trust model.

Model access

Model requests pass through a controlled Odella service boundary. Worker environments are not provisioned with direct model-provider credentials. Available models and worker model selections remain subject to workspace and worker configuration. See Models and Model & Intelligence settings.

Data residency and international processing

Data residency, international transfers, support access, customer-selected services, and Subprocessor locations are governed by the applicable contractual terms and account configuration. Do not assume that choosing a region prevents every transfer. Customer-selected model providers and integrations may process data in locations governed by their own terms and configuration. Review:
  • Privacy Policy for current privacy, residency, retention, and individual-rights information
  • Data Processing Addendum for processing roles, security terms, international-transfer mechanisms, breach obligations, and deletion terms
  • Subprocessors for how the current list and change-notice process are managed
  • Trust Center for current assurance and Subprocessor information

Monitoring, audit, and resilience

Odella records relevant operational and security events to support monitoring, troubleshooting, access review, and incident response. Platform controls include protected logging, monitored services, bounded retries, recovery mechanisms, and separation of durable customer state from replaceable worker execution. The product’s Activity Log gives authorized users a worker-level view of conversations, tasks, workflows, and service events. It is not a replacement for the broader assurance material available through the Trust Center.

Shared responsibility

1

Assign accountable owners

Identify an organization administrator, security contact, integration owner, and manager for each production worker.
2

Start with minimum access

Assign only the workflows, knowledge, templates, applications, and tools required for the role.
3

Review external services

Evaluate each integration and custom MCP server before connecting it, including the provider’s terms, permissions, hosting, retention, and subprocessors.
4

Require approval where needed

Keep people in the approval path before external sends, sensitive writes, destructive operations, or decisions requiring authorization.
5

Test representative work

Verify normal, failure, and escalation paths with non-sensitive data before production use.
6

Review access and activity

Periodically review administrators, worker assignments, integration connections, saved approval rules, and worker Activity.
7

Revoke promptly

Disable workers, disconnect integrations, rotate credentials, and remove user access when responsibilities change.

Trust Center

Review current security and compliance assurance information and the authoritative Subprocessor register.

Data Processing Addendum

Review processing roles, technical and organizational measures, breach terms, transfers, deletion, and audit rights.

Privacy Policy

Review how Odella collects, uses, protects, retains, and transfers personal information.

Subprocessors

Review the Subprocessor-list process, change notices, and contact information.

Terms of Use

Review the terms governing use, customer responsibilities, security, data protection, and third-party services.

Security review support

Contact Odella for product questions or to coordinate an enterprise security review.
For privacy and Data Subject requests, contact dsar@odella.ai. For legal and DPA questions, contact legal@odella.ai.