Snapshot 19007
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to content For business owners What UpBoard reads, and what it never does without you What happens during a scan 1. Your credentials Sent over HTTPS, encrypted on receipt 2. The scan Read-only access to your Odoo 3. The result Score and detected anomalies 4. Expiry Access token unusable after 30 min Read-only The scan and the agents' analyses only use Odoo read operations (search_read). Nothing is created, modified or deleted in your instance. Human approval for every write When an agent proposes an action in Odoo (create, update, delete, method execution), it waits for your explicit approval. This control cannot be bypassed. Protected credentials For the free scan, your API key is never saved to our database during the scan: it only lives in an encrypted token that becomes unusable after 30 minutes. If the scan succeeds and you create and connect your account within the 30 minutes that follow the launch, this access connects your agents without retyping it, then stays encrypted like any Odoo connection of your account. Otherwise it is erased. We keep your Odoo address, the database name and the login used, so you do not have to type them again. No copy of your database UpBoard queries Odoo at analysis time and does not duplicate your database. It keeps the useful result: score, detected anomalies (with the related references and amounts) and, for an account, alerts and agent memory. An API key you can revoke We recommend an Odoo API key rather than a password. You can revoke it anytime from your Odoo user's preferences, which cuts access immediately. Hosted in Switzerland The platform is hosted by Infomaniak in Geneva. Switzerland benefits from a European Commission adequacy decision under the GDPR. For your IT team The technical brief What an Odoo administrator or IT manager checks before approving the integration. Integration and architecture Connection to your Odoo through the standard JSON-RPC API. No module to install on the Odoo side. Odoo 15 to 20, Community and Enterprise. The connector detects the version and available fields. Your instance must be reachable from the Internet (Odoo Online, Odoo.sh or an exposed server). Private network addresses are rejected. We recommend a dedicated Odoo user with read rights on the modules to analyse. Without write rights, no write is technically possible. The connector is the only access point to your ERP. It blocks sensitive models (system parameters, mail servers, user API keys) and redacts secret fields before any caching. Customer isolation: every record carries its customer ID and every query filters on it, a rule checked automatically in continuous integration. Encryption In transit: TLS between your browser and UpBoard, and to your Odoo when its URL uses https. ERP credentials encrypted at rest (Fernet), with a key rotation mechanism. UpBoard passwords hashed (bcrypt), never stored in clear text. Daily backups encrypted (AES-256) before leaving the server. Hosting and subprocessors Hosted by Infomaniak in Geneva (Switzerland). Infomaniak is ISO 27001 certified. Analyses are generated by Anthropic's Claude models (United States) through the commercial API, under standard contractual clauses. Agent memory is indexed with OpenAI embeddings. Your data is never used to train any model. Off-site backup copy on Google Drive, encrypted before upload: Google does not hold the key. Emails, phone numbers, IBANs and national IDs are masked in logs. Website audience measurement with Google Analytics, loaded only after your consent. Full list of subprocessors in the privacy policy. Authentication and access Access to UpBoard through short sessions (JWT) and roles (owner, admin, member). Changing or resetting a password invalidates earlier sessions. Two-factor authentication with a code sent by email (valid for 5 minutes). Off by default: each user can turn it on in their settings, and an admin can require it for the whole organisation. GDPR compliance Data minimisation: no copy of your database, only analysis results. Right of access and erasure on request at [email protected]. When the subscription ends, or when the trial expires without subscribing, all account data is deleted 90 days later. Email notification without undue delay of an incident affecting your data. No SOC 2 or ISO 27001 certification for UpBoard at this stage. Internal security audit carried out in June 2026, fixes deployed to production. Disclosure policy Report a vulnerability Think you have found a security issue in UpBoard? Write to us at [email protected], the address also published in our security.txt file. Please describe the issue, the steps to reproduce it and its possible impact. We acknowledge your report within 5 business days. We take no legal action against research carried out in good faith and within this policy. Do not access, modify or keep other customers' data: stick to the minimum needed to demonstrate the issue. Do not degrade the service: no denial of service, no mass automated testing, no social engineering aimed at our customers or at us. Give us time to fix the issue before any publication. We do not run a reward programme (bug bounty). Frequently asked questions Can the scan modify my Odoo data? No. The scan reads your data with Odoo's search_read operation and writes nothing. Writes later proposed by the agents always wait for your explicit approval. Are my Odoo credentials kept after the scan? Your API key is encrypted on receipt and never saved to our database during the scan. If the scan succeeds and you create and connect your account within the 30 minutes that follow the launch, it connects your agents without retyping it, then stays encrypted like any Odoo connection of your account. Otherwise the encrypted token holding it is erased after 30 minutes at most. We keep your Odoo address, the database name and the login used, deleted with the diagnostic (after 30 days if it stays anonymous, after at most 12 months if you left your contact details without creating an account). A dedicated API key can be revoked anytime in Odoo. Does my data leave Europe? The platform and its database are hosted in Switzerland, by Infomaniak in Geneva. To generate analyses, requests to AI models go through Anthropic's and OpenAI's commercial APIs in the United States, under standard contractual clauses. Do I need to install a module in Odoo? No. UpBoard uses Odoo's standard JSON-RPC API. All it needs is a URL reachable from the Internet and an API key, ideally for a dedicated user. Is UpBoard SOC 2 or ISO 27001 certified? No, not at this stage. Our host Infomaniak is ISO 27001 certified, and UpBoard went through an internal security audit in June 2026. Learn more Architecture and security Hosting GDPR compliance Odoo integration Privacy policy See it on your own Odoo Run a free read-only scan, or bring your technical questions to a demo with the founder. Scan my Odoo for freeBook a technical demo