Security and compliance

Odoo Security Audit

Odoo secures the platform. We audit the part you own: access rights, record rules, custom modules, hosting configuration, API keys and backups.

See the packages

The Odoo platform holds up well. Odoo SA runs Tier III data centres, encrypts data at rest and in transit, publishes security advisories and patches vulnerabilities. In almost every breach we see, the weakness is not in the product. It is in the deployment.

Permissions granted "temporarily" and never revoked. A database manager left reachable. A third-party app installed without review. A backup nobody has ever actually restored. These are configuration problems, and they are yours to own on any hosting plan.

Looking for a performance and optimisation review instead? That is our general Odoo audit. This page covers security and compliance only. The two combine if you need both.

What Odoo covers, what stays yours

The dividing line moves between Odoo Online, Odoo.sh and self-hosted. The right-hand column never moves.

Odoo SA handles

  • Physical security and Tier III data centres
  • Encryption at rest and in transit
  • Framework patches and security advisories
  • Platform availability and redundancy

You stay responsible for

  • Who holds which group and access right
  • The record rules that filter your data
  • Custom code that bypasses the ORM
  • Accounts, two-factor enforcement and API keys
  • Third-party apps you install
  • Data retention and tested restores

What we review

Nine control areas, each assessed against a defined Odoo control set rather than a generic checklist.

Access rights and groups

Every group, inherited or implied, checked against what people actually do. Access granted temporarily and never revoked surfaces here.

Record rules

The global and per-group rules deciding which rows a user sees. One badly scoped rule exposes an entire company.

Custom modules

Code review for unjustified sudo(), raw SQL, unsafe computed fields and controllers without authentication.

Hosting configuration

Database manager exposure, master password, proxy headers, TLS, open ports and logging.

Accounts and authentication

Dormant, shared and contractor accounts, two-factor enforcement, password policy and SSO integration.

API keys and integrations

Key scope and rotation, which external systems read your data and which user they authenticate as.

Third-party apps

Provenance, maintenance status and requested permissions for every module installed from the Odoo App Store or elsewhere.

Backups and restore

Frequency, location, encryption and, above all, a real restore test on a separate environment.

Retention and processing

Retention periods, audit logs, deletion on request and where personal data physically lives.

What we need from you

Gather these before kickoff and the audit lands inside the stated timeline. Nothing here requires write access to your production system.

Read-only access

A dedicated user with read rights, or a configuration export. No write access to production is requested.

A recent database copy

Anonymised where possible. This is what lets the review run offline without touching your live system.

The custom module repository

Read access to the Git repository, or an archive of installed modules with their versions.

Hosting details

Odoo Online, Odoo.sh or self-hosted, with network topology and provider if you run it yourself.

The integration inventory

Systems that read or write over API, webhooks or connectors, and the account each one uses.

An interview slot

About 60 minutes with your Odoo administrator and, if separate, whoever owns the infrastructure.

A non-production environment

A staging instance where the restore test can run without touching production.

Your compliance obligations

Which frameworks apply to you, any audits already passed and findings still open.

If something is missing we record it in the report as a blind spot rather than assuming it is fine.

How the audit runs

Durations shown for a Full Security Audit. The Essentials Review compresses steps 2 and 3, Compliance Assurance extends steps 4 and 5.

01

Days 1 to 2

Scoping and access

Scoping call, read-only access set up, the items listed above collected and the scope frozen.

02

Days 3 to 6

Configuration review

Access rights, record rules, accounts, two-factor enforcement and API keys worked through on the database copy.

03

Days 5 to 9

Code and hosting

Custom module and third-party app review, then hosting hardening and network exposure.

04

Days 8 to 11

Restore test

A real backup restored to a separate environment, with recovery time measured and integrity checked.

05

Days 12 to 15

Report and walkthrough

Prioritised risk register, remediation plan sized in effort, and a walkthrough session with your team.

Three levels of depth

Scope follows your user count, custom modules and integrations. Quoting follows a 20-minute scoping call.

Essentials Review

The most common risks, quickly

About 1 week

  • Access rights and record rules
  • Accounts and two-factor enforcement
  • Database manager exposure
  • Backup verification
  • Prioritised risk register
Scope this audit

Compliance Assurance

For an external audit ahead

3 to 4 weeks, then quarterly

  • Everything in Full Security Audit
  • SOC 2, ISO 27001, GDPR, PIPEDA mapping
  • Evidence pack for your auditors
  • Quarterly access review
  • Remediation tracking report
Scope this audit

Findings mapped to your frameworks

Every finding carries a control reference, so the report feeds your compliance work directly instead of sitting beside it.

SOC 2

Logical access controls, change management and monitoring mapped to the Security and Confidentiality criteria.

ISO 27001

Findings aligned to the Annex A controls that matter for an ERP, principally A.5, A.8 and A.9.

GDPR

Lawful basis, minimisation, retention periods, right to erasure and the processing record for Odoo data.

PIPEDA

Consent, purpose limitation and safeguards for organisations operating in Canada.

What you get

Risk register

Every finding rated by severity and exploitability, with the concrete attack path rather than a generic label.

Remediation plan

Fixes ordered by effort against risk, sized in days, runnable by your team or ours.

Evidence pack

Screenshots, configuration extracts and control references, ready to hand to an external auditor.

Live walkthrough

A session with your technical and executive stakeholders, so decisions do not stay buried in a PDF.

Backed by real migrations

Numbers like yours, validated on real migrations

These are three engagements where the projection actually turned into operational reality on Odoo, and the full case studies live on the migration service page.

  • ManufacturingV12 → V17

    Industrial Manufacturer, Texas

    12custom modules carried over, zero data lost

  • DistributionV14 → V18

    Wholesale Distributor, Quebec

    30%faster page loads once the upgrade shipped

  • Professional ServicesCE → Enterprise

    Consulting Firm, Brussels

    0hproduction downtime during cutover

Start with a scoping call

Twenty minutes to pin down your deployment, user count and compliance obligations. You leave with a scope and a timeline, no commitment.

Book the call

Frequently asked questions

  • 01

    Is Odoo secure?

    Odoo the platform holds up well. Odoo SA runs Tier III data centres, encrypts data at rest and in transit, publishes security advisories and patches vulnerabilities. The weakness in almost every breach sits in the deployment, not the product: over-granted permissions, an exposed database manager, an unvetted app, an untested backup.

  • 02

    We are on Odoo Online. Do we still need an audit?

    Yes. Odoo Online removes your infrastructure and patching burden. Your access model, user accounts, two-factor enforcement, API keys, third-party apps and data retention stay entirely yours. That is where the majority of findings sit.

  • 03

    Will an Odoo security audit disrupt our operations?

    No. The work runs from read-only access and a copy of your configuration wherever possible, plus a short interview with your administrator and a scheduled restore test on a separate environment.

  • 04

    Is an Odoo security audit the same as a penetration test?

    No. A penetration test attacks your perimeter to prove exploitability. A security audit reviews configuration against a defined Odoo control set. Most Odoo risk lives in configuration, not at the perimeter.

  • 05

    How long does an Odoo security audit take?

    An Essentials Review runs about a week from access to report. A Full Security Audit runs two to three weeks. Compliance Assurance runs three to four weeks, then continues with quarterly access reviews.