Security and compliance
Odoo Security Audit
Odoo secures the platform. We audit the part you own: access rights, record rules, custom modules, hosting configuration, API keys and backups.
See the packagesThe Odoo platform holds up well. Odoo SA runs Tier III data centres, encrypts data at rest and in transit, publishes security advisories and patches vulnerabilities. In almost every breach we see, the weakness is not in the product. It is in the deployment.
Permissions granted "temporarily" and never revoked. A database manager left reachable. A third-party app installed without review. A backup nobody has ever actually restored. These are configuration problems, and they are yours to own on any hosting plan.
Looking for a performance and optimisation review instead? That is our general Odoo audit. This page covers security and compliance only. The two combine if you need both.
What Odoo covers, what stays yours
The dividing line moves between Odoo Online, Odoo.sh and self-hosted. The right-hand column never moves.
Odoo SA handles
- Physical security and Tier III data centres
- Encryption at rest and in transit
- Framework patches and security advisories
- Platform availability and redundancy
You stay responsible for
- Who holds which group and access right
- The record rules that filter your data
- Custom code that bypasses the ORM
- Accounts, two-factor enforcement and API keys
- Third-party apps you install
- Data retention and tested restores
What we review
Nine control areas, each assessed against a defined Odoo control set rather than a generic checklist.
Access rights and groups
Every group, inherited or implied, checked against what people actually do. Access granted temporarily and never revoked surfaces here.
Record rules
The global and per-group rules deciding which rows a user sees. One badly scoped rule exposes an entire company.
Custom modules
Code review for unjustified sudo(), raw SQL, unsafe computed fields and controllers without authentication.
Hosting configuration
Database manager exposure, master password, proxy headers, TLS, open ports and logging.
Accounts and authentication
Dormant, shared and contractor accounts, two-factor enforcement, password policy and SSO integration.
API keys and integrations
Key scope and rotation, which external systems read your data and which user they authenticate as.
Third-party apps
Provenance, maintenance status and requested permissions for every module installed from the Odoo App Store or elsewhere.
Backups and restore
Frequency, location, encryption and, above all, a real restore test on a separate environment.
Retention and processing
Retention periods, audit logs, deletion on request and where personal data physically lives.
What we need from you
Gather these before kickoff and the audit lands inside the stated timeline. Nothing here requires write access to your production system.
Read-only access
A dedicated user with read rights, or a configuration export. No write access to production is requested.
A recent database copy
Anonymised where possible. This is what lets the review run offline without touching your live system.
The custom module repository
Read access to the Git repository, or an archive of installed modules with their versions.
Hosting details
Odoo Online, Odoo.sh or self-hosted, with network topology and provider if you run it yourself.
The integration inventory
Systems that read or write over API, webhooks or connectors, and the account each one uses.
An interview slot
About 60 minutes with your Odoo administrator and, if separate, whoever owns the infrastructure.
A non-production environment
A staging instance where the restore test can run without touching production.
Your compliance obligations
Which frameworks apply to you, any audits already passed and findings still open.
If something is missing we record it in the report as a blind spot rather than assuming it is fine.
How the audit runs
Durations shown for a Full Security Audit. The Essentials Review compresses steps 2 and 3, Compliance Assurance extends steps 4 and 5.
Days 1 to 2
Scoping and access
Scoping call, read-only access set up, the items listed above collected and the scope frozen.
Days 3 to 6
Configuration review
Access rights, record rules, accounts, two-factor enforcement and API keys worked through on the database copy.
Days 5 to 9
Code and hosting
Custom module and third-party app review, then hosting hardening and network exposure.
Days 8 to 11
Restore test
A real backup restored to a separate environment, with recovery time measured and integrity checked.
Days 12 to 15
Report and walkthrough
Prioritised risk register, remediation plan sized in effort, and a walkthrough session with your team.
Three levels of depth
Scope follows your user count, custom modules and integrations. Quoting follows a 20-minute scoping call.
Essentials Review
The most common risks, quickly
About 1 week
- Access rights and record rules
- Accounts and two-factor enforcement
- Database manager exposure
- Backup verification
- Prioritised risk register
Full Security Audit
All nine control areas
2 to 3 weeks
- Everything in Essentials
- Custom module code review
- Hosting hardening
- API keys and integrations
- Real restore test
- Remediation plan sized in effort
Compliance Assurance
For an external audit ahead
3 to 4 weeks, then quarterly
- Everything in Full Security Audit
- SOC 2, ISO 27001, GDPR, PIPEDA mapping
- Evidence pack for your auditors
- Quarterly access review
- Remediation tracking report
Findings mapped to your frameworks
Every finding carries a control reference, so the report feeds your compliance work directly instead of sitting beside it.
SOC 2
Logical access controls, change management and monitoring mapped to the Security and Confidentiality criteria.
ISO 27001
Findings aligned to the Annex A controls that matter for an ERP, principally A.5, A.8 and A.9.
GDPR
Lawful basis, minimisation, retention periods, right to erasure and the processing record for Odoo data.
PIPEDA
Consent, purpose limitation and safeguards for organisations operating in Canada.
What you get
Risk register
Every finding rated by severity and exploitability, with the concrete attack path rather than a generic label.
Remediation plan
Fixes ordered by effort against risk, sized in days, runnable by your team or ours.
Evidence pack
Screenshots, configuration extracts and control references, ready to hand to an external auditor.
Live walkthrough
A session with your technical and executive stakeholders, so decisions do not stay buried in a PDF.
Backed by real migrations
Numbers like yours, validated on real migrations
These are three engagements where the projection actually turned into operational reality on Odoo, and the full case studies live on the migration service page.
- ManufacturingV12 → V17
Industrial Manufacturer, Texas
12custom modules carried over, zero data lost
- DistributionV14 → V18
Wholesale Distributor, Quebec
30%faster page loads once the upgrade shipped
- Professional ServicesCE → Enterprise
Consulting Firm, Brussels
0hproduction downtime during cutover
Start with a scoping call
Twenty minutes to pin down your deployment, user count and compliance obligations. You leave with a scope and a timeline, no commitment.
Frequently asked questions
01
Is Odoo secure?
Odoo the platform holds up well. Odoo SA runs Tier III data centres, encrypts data at rest and in transit, publishes security advisories and patches vulnerabilities. The weakness in almost every breach sits in the deployment, not the product: over-granted permissions, an exposed database manager, an unvetted app, an untested backup.
02
We are on Odoo Online. Do we still need an audit?
Yes. Odoo Online removes your infrastructure and patching burden. Your access model, user accounts, two-factor enforcement, API keys, third-party apps and data retention stay entirely yours. That is where the majority of findings sit.
03
Will an Odoo security audit disrupt our operations?
No. The work runs from read-only access and a copy of your configuration wherever possible, plus a short interview with your administrator and a scheduled restore test on a separate environment.
04
Is an Odoo security audit the same as a penetration test?
No. A penetration test attacks your perimeter to prove exploitability. A security audit reviews configuration against a defined Odoo control set. Most Odoo risk lives in configuration, not at the perimeter.
05
How long does an Odoo security audit take?
An Essentials Review runs about a week from access to report. A Full Security Audit runs two to three weeks. Compliance Assurance runs three to four weeks, then continues with quarterly access reviews.