SECURITY & DATA HANDLING

Know how your client’s
data is being handled.

Taking responsibility for a migration means asking a few sensible questions about the tools involved. Here’s how OdooMap handles access, AI requests and changes to your target system.

What goes to the AI provider

OdooMap’s Claude integration works with descriptions of columns rather than uploaded rows. The request includes headers, inferred types, detected patterns and target field metadata for unmatched columns and uncertain pairings. High-confidence matches and pairings previously confirmed by your project’s reviewers are kept out of that review.

Before a request leaves OdooMap, source cell values are reduced to masked shapes or length ranges. Reference values can also receive project-specific tokens to describe repeated keys. The request excludes file names, project names, user identities and connection credentials. Open “What the AI sees” on a mapping set to inspect the payload without calling the provider.

This reduces exposure, but it does not make the request anonymous. Column headers and field metadata can still contain sensitive business context. External AI is disabled by default and requires provider credentials and operator confirmation of the applicable training and retention arrangements. Contact us if your client has requirements around provider use or retention.

How suggestions become changes

AI output is checked against real source columns and writable target fields before it appears as a suggestion. The provider cannot confirm a mapping or write to Odoo. Your team reviews the mappings, and a project administrator must explicitly approve a validated migration proposal before execution. Built-in mapping and validation continue to work when the AI provider is unavailable.

Who can access a project

Authenticated API requests check project membership. Organization roles manage the team and billing, while project roles separately control access and approval. Connection grants restrict the permitted target and fields, so joining an organization does not automatically open every client project.

Credentials, sessions and source files

Saved Odoo credentials are encrypted by the backend, and uploaded source files are stored privately. Browser refresh sessions use encrypted HttpOnly cookies, with access tokens held in memory. Source files are not served as public website assets.

What archiving and cancellation mean for your data

Project administrators can delete supported source artifacts. Archiving a project or cancelling a subscription does not delete its data; migration evidence and backup retention need separate handling. Talk to us about specific deletion requirements before uploading sensitive client data.

Test against the system you’ll actually use

Use representative data in a sandbox with your Odoo version, modules and permissions before production work. Odoo business actions can have side effects without a universal rollback, and compatibility needs checking for each implementation. We do not claim security certification or support for every possible Odoo configuration.

Talk through your security requirements with us