Security · Last updated August 23, 2026
This statement sets out the technical and organisational measures Alano Tech Pte. Ltd. applies to customer mail in Omucloud, the parties able to access that mail, and the controls the service does not currently hold.
- Encryption
- TLS in transit, encrypted at rest
- Tenant isolation
- Enforced by the database, not by app code
- Infrastructure
- SOC 2 Type 2 · ISO/IEC 27001 providers
- Tracking
- No analytics, no telemetry, no AI

Material disclosures
- Omucloud is not end-to-end encrypted.Message content is encrypted in transit and at rest, but remains readable by the service. Where confidentiality from the provider is a requirement, end-to-end encryption must be applied above the mail service, including this one.
- Certification sits with our infrastructure providers.Your mail is stored and delivered on infrastructure operated by Supabase and Resend. Supabase is SOC 2 Type 2 compliant, ISO/IEC 27001 certified and HIPAA compliant; Resend is SOC 2 Type II compliant and commissions third-party penetration testing. Those attestations cover their platforms — the Omucloud application layer Alano Tech Pte. Ltd. writes and operates is not separately certified, and is recorded under “Controls not yet in place” below.
Controls in place
Each control below is implemented and operating as at the date of this statement.
Encryption in transit
Every connection to Omucloud uses TLS, and browsers are told never to try an unencrypted one. Mail travelling between providers is encrypted where the other server supports it — the same limit that applies to all email.
Encryption at rest
Messages and attachments sit on encrypted infrastructure. This protects the stored data, but it is not per-mailbox encryption and it does not stop us reading your mail.
Authentication
Sign-in is by email and password, handled by our authentication provider. We never hold your password in readable form. New addresses on our shared domain are confirmed by a single-use code.
Repeated sign-in attempts
Repeated failed sign-ins are throttled, per address and per network, on top of the limits our authentication provider applies. A failed attempt never reveals whether an address exists. The thresholds are deliberately not published.
Tenant isolation
Separation between accounts is enforced by the database, not by application code remembering to filter. A message is readable only by the accounts it was actually delivered to.
Domain verification
A custom domain works only after you publish DNS records that only its owner can publish. Until it verifies, it cannot send and no mailbox can be created on it.
Sending integrity
Your sending address always comes from your own account and can never be set by a request. Nobody can send as you, or as your domain.
Attachments
Only a fixed list of file types is accepted. Programs and scripts are refused in both directions, and files are checked against their own contents rather than their name. We do not run malware scanning.
Opening a message safely
Message content is cleaned before it is shown, and a sender's styling cannot escape the message to alter the app around it. Remote images still load, so a sender can tell when you opened their mail.
Keys and credentials
Credentials that reach your data live only on our servers. They are never in the app you download and never in our source code.
Abuse limits
Sending is capped per account, so one misused account cannot damage delivery for everyone else. Incoming mail is cryptographically verified and rejected if it is not genuine.
Access to customer mail
Omucloud makes no claim that it is technically incapable of reading customer mail. A provider asserting such an incapacity should be asked to identify the cryptographic mechanism that produces it.
Administrative access
A small number of personnel hold administrative access to production systems, and that access is technically capable of reaching message content. It is restricted by internal policy to four purposes: investigating a delivery failure reported by the account holder, investigating suspected abuse, responding to a lawful order or direction, and restoring the service during an incident. Access for any other purpose is prohibited and is a disciplinary matter.
Customer mail is not read to construct user profiles, is not sold or disclosed for commercial purposes, and is not used to train machine-learning models. Omucloud incorporates no artificial-intelligence or language-model component of any kind.
Administrative access to message content is not recorded in an audit log. There is accordingly no record against which such access could be reviewed after the event.
Parties with no access
Message content is not written to application logs. Omucloud incorporates no analytics package, no error-monitoring service, no tracking pixel and no advertising tag. No third party therefore receives message content as a by-product of instrumentation.
Storage, retention and deletion
Data stored
Sent and received mail, comprising subject lines, full message bodies and attachments, together with the transmission details of each message: sender, recipients and time of delivery. Also stored: the account address, company name and signature where set, calendar entries, and the original sign-up record.
Deletion of an individual message
Not supported. Mail is retained for the life of the account. Individual attachments may be deleted from Settings, and the account may be deleted in full.
Deletion of an account
An account holder may delete their account from Settings without contacting us. The operation requires the account password and a typed confirmation, and removes received mail, sent mail, attachments, calendar entries and the account record.
Two consequences follow from deletion. A message delivered to more than one Omucloud account is removed from the deleting account only and is retained by the other recipients, to whom it also belongs. Where the account holds a custom domain, deletion removes every mailbox on that domain.
Backups
Deletion takes effect immediately in live systems. Backup snapshots are held by our database provider under its own retention schedule, and deleted data persists in those snapshots until they expire. No figure is published for that window: the schedule is the provider’s default and is not a commitment we are in a position to give.
Subprocessors
Operating a mail service requires third-party infrastructure. The following list is exhaustive as at the date of this statement.
| Provider | Purpose | Data handled |
|---|---|---|
| Resend | Sending and receiving email | Message content, attachments, senders and recipients |
| Supabase | Database, sign-in, file storage | Messages, attachments, account records |
| Cloudflare | Hosting and network | Traffic in transit, IP addresses |
| Apple | iOS push notifications | Device tokens, sender and subject in the alert |
| Google Fonts | Typeface on public pages only | Browser IP address. Not used once signed in |
Certification held by these providers, verified against their published trust documentation: Supabase is SOC 2 Type 2 compliant, ISO/IEC 27001 certified and HIPAA compliant. Resend is SOC 2 Type II compliant and commissions independent penetration testing. Those attestations cover the providers’ own platforms.
A signed data processing agreement is not currently offered. Where one is required for procurement, contact us and we will discuss what can be put in place.
Vulnerability disclosure
Suspected vulnerabilities should be reported to us before publication. Write to security@omucloud.co with sufficient detail to reproduce the issue. We will acknowledge receipt, provide progress updates, and confirm when the issue is resolved.
We will not pursue legal action against a researcher who reports in good faith, does not access or alter data belonging to others, and allows a reasonable period for remediation before disclosure. No paid bounty programme is operated. Credit is given on request.
Reports of spam or misuse of the service should be sent to hello@alano.ai. Requests relating to personal data are dealt with under the Privacy Policy.
Controls not yet in place
Neither of the following is implemented.
Independent penetration testing
PlannedTo be performed by an external firm, with the summary report made available to customers on request. A review conducted by the authors of the code does not constitute an independent test and is not presented as one.
SOC 2 readiness
PlannedNot commenced, and no target date has been set. This item will be described as in progress only once work has begun.
Basis of this statement
Each control stated above has been verified against the source code operating the service. That verification is an internal review. It is not an independent audit, an attestation or a penetration test, and it is not presented as any of those. This statement is accurate as at the date shown at the head of the page and is amended when a control changes.
Who operates Omucloud
Omucloud is an Alano product, built and operated by Alano Tech Pte. Ltd., a company incorporated in Singapore. Alano and Opptymizer are sister companies sharing a founding team — Opptymizer is an enterprise CRM, CDP and AI consultancy working across Singapore, Malaysia and Australia.
Opptymizer is a Salesforce Partner, an OpenAI Select Partner and a Notion Solutions Partner.
These partnerships are held by Opptymizer, not by Omucloud. Salesforce, OpenAI, Notion and related marks are trademarks of their respective owners.


