Legal

Security Policy

What Owwel commits to on security, how to report a problem, and what we deliberately do not claim.

Last updated 26 August 2026

1. What Owwel commits to

  • Encrypting your data in transit and at rest.
  • Enforcing separation between businesses at the database, so a mistake in the application cannot expose one customer's rows to another.
  • Granting access by role, feature by feature, rather than as one blanket login.
  • Requiring a one-time code when signing in from an unrecognised device, even with the correct password.
  • Expiring sessions on a fixed window rather than letting them run forever.
  • Keeping an automatic audit trail of who changed what, written by the database as the change happens.
  • Never storing your password in a readable form.

Each of these is described in detail, including where its limits are, in the Security Center.

2. Reporting a vulnerability

If you believe you have found a security problem in Owwel, tell us before you tell anyone else.

  • Write to info@owwel.com with what you found and how to reproduce it.
  • We will acknowledge that we received it.
  • We will tell you what we found when we have looked, and what we intend to do.
  • We will tell you when it is fixed.

3. Good faith research

Research carried out in good faith will not be met with a legal threat. To stay within that, please:

  • Test only against your own account and your own data.
  • Do not access, modify or delete anyone else's data. If you reach someone else's data by accident, stop, and tell us.
  • Do not degrade the service for others, and do not run denial-of-service tests.
  • Give us a reasonable chance to fix the issue before making it public.

Owwel does not currently run a paid bug bounty. We will not pretend otherwise to attract reports, and we will credit you if you would like us to.

4. If something happens

  • We contain first. Access is cut or credentials rotated before anybody starts working out the cause.
  • We establish scope: what was reachable, by whom, and for how long.
  • We tell affected customers what happened, what was reached and what to do. We do not wait for a complete picture before saying something happened.
  • We fix the cause, not only the symptom.

Where Owwel processes data on your behalf, the notification terms are set out in the Data Processing Policy.

5. What Owwel does not claim

Owwel is not certified against SOC 2, ISO 27001 or PCI DSS, and does not hold itself out as being. A certification is an audited thing, and we will say so here on the day we have one.

  • Owwel does not process card payments, so no card numbers are stored in it.
  • Owwel does not currently offer a contractual uptime guarantee.
  • Monitoring means faults are reported automatically. It does not mean a person is watching a screen overnight.

We would rather be believed on the controls we do have than be caught overstating one we do not.

6. Your part

Most real-world account compromises start on the customer's side, not the platform's.

  • Use a password you do not use anywhere else.
  • Give each team member their own login instead of sharing one. Otherwise the audit trail cannot tell you who did what.
  • Grant the narrowest role that lets someone do their job, and remove access when they leave.
  • Keep the email address on the account current, because that is where sign-in codes and resets go.

Who you are contracting with

Trading name
Owwel
Privacy and data requests
info@owwel.com
Report a security issue
info@owwel.com