oddly

Security

oddly is built by a security operator. Encryption, least-privilege access, audit-first design, and a responsible disclosure pathway are not retrofits; they are how the platform was put together.

Last updated: 2026-04-28.

Designed with PDPA, GDPR, and SOC 2 principles in mind. oddly is not yet formally certified to SOC 2 or ISO 27001. The control set we operate against, including access management, encryption, vendor management, audit logging, and incident response, is patterned on those frameworks. Formal attestation lands once the customer base justifies the cost.

Infrastructure

The Service runs entirely on Cloudflare's developer platform. There is no traditional server fleet to compromise.

Encryption

Authentication + access

Webhook integrity

Every inbound webhook (Stripe, Shopify, Meta) is verified with an HMAC signature using Web Crypto before any side effect runs. Replays are dropped at the edge.

Action reversibility

Every change the platform writes to a Connected Source is recorded as an audit_entry with the action, actor, reasoning, and reversibility tag. Reversible actions can be rolled back from the dashboard.

Rate limits

Per-account and per-IP rate limits are applied at the edge. The action queue is independently capped per plan tier so a runaway script cannot exhaust your monthly action budget.

Log hygiene

Application logs are scrubbed of credentials, OAuth tokens, webhook signing secrets, and email payload bodies before being written. Server-side request logs are retained for 30 days for diagnostics.

Vulnerability management

Operations + incident response

Subprocessors

The current subprocessor list and the data each handles is published in section 7 of the Privacy Policy.

Compliance posture

Responsible disclosure

If you've found a security issue in oddly, please report it. We treat researchers as collaborators.

Where to send it

Email security@myoddlyeven.com. Subject line: SECURITY: followed by a one-line summary.

What to include

What we commit to

Out of scope

Contact

Security: security@myoddlyeven.com.

General: subscriptions@myoddlyeven.com.