Trust

Security

Review the security controls on outcomatic.com and the requirements to establish for a business-system integration. Keep data access, permitted actions, and operational evidence within clearly defined boundaries.

Security teams · Technical architects · Enterprise buyersContact the team

Website controls

The site is served over HTTPS. Its Worker sets a Content Security Policy that restricts scripts and styles to first-party sources, disallows embedded objects, and prevents framing. Response headers also disable MIME sniffing and restrict browser access to camera, microphone, and geolocation.

DNSSEC is enabled for the domain. The workflow explorer runs in the browser with sample data and holds no ERP credentials. Contact and support forms are intended for non-sensitive inquiries.

Integration security requirements

Review authentication, role management, credential storage, tenant boundaries, encryption, logging, and incident responsibilities for the intended deployment. Match each requirement to an implementation and the evidence needed to assess it.

  • Scope contracts, connections, inputs, runs, and receipts to the customer and company identity.
  • Authorize only the reads and actions required by the task contract.
  • Treat documents and model output as untrusted data, not a source of new permissions.
  • Keep model routing within configured data boundaries and approved processing destinations.
  • Exclude credentials and unnecessary document contents from operational evidence.

Security review

Review the deployment and data flow for your workload. Identify which providers can receive which fields, how destination credentials are scoped and rotated, how authorization is checked during retries, and which records support an investigation after an uncertain write.

Bring requirements for access reviews, independent testing, recovery, vulnerability management, and subprocessors to the technical discussion. For each requirement, identify the responsible party, assessment scope, and supporting evidence.

Reporting a suspected security issue

Use the support contact page to identify a security concern and provide the affected URL, a concise description, and non-sensitive reproduction information. Do not include production secrets, personal records, or exploit payloads in the initial message. The team can coordinate an appropriate channel for additional detail.

If you believe a credential has been exposed, revoke it through the system that issued it. Keep testing within systems and accounts you are authorized to assess, and include only the minimum information needed to reproduce a suspected issue.

Missing a detail or found a problem?

Send a documentation question →

Define the first outcome together.

Talk through its inputs, decision boundaries, and definition of completion with the team.

Contact the team

Search Outcomatic

Search products, documentation, articles, and help.

Open full search pageEsc to close

Analytics preferences

Optional analytics help us understand which pages and journeys are useful. They are off by default.

When enabled, we count page views and selected actions by page and day. We do not store visitor identifiers, search terms, form contents, or cookies in analytics. Your browser’s Do Not Track or Global Privacy Control signal takes priority.

Allow anonymous aggregate analytics?

Read the website privacy notice