Security
Your passwords stay with you. Not your agents.
OLMS exists to reduce the number of people who can misuse a supplier login. Here is how it does that, in plain language.
[sample copy: pending confirmation from the engineering team]
- Where credentials live
- Supplier usernames and passwords are encrypted at rest on OLMS servers. They are decrypted only at the moment OLMS logs an agent in, and are never sent to the agent's browser as readable text.
- Who can see them
- Nobody on the agent side. Only named OLMS administrators in your agency can add or change a supplier credential, and every change is logged with who made it and when.
- What is recorded
- Each login, page visit and booking action is stored against the agent, the supplier portal and the time. Logs are read-only to everyone, including administrators.
- Session control
- Sessions end when an agent is disabled, when shift hours end, or when an administrator ends them. Disabling an agent takes effect immediately across every mapped portal.
- Hosting and data
- Hosting region, backup schedule and retention period are shared in writing during onboarding.
Bring your IT lead to the demo.
We will walk through the security model and answer questions in writing.