Skip to Content
Odoo เมนู
  • ลงชื่อเข้าใช้
  • Odoo Experience
  • แอป
    การเงิน
    • ระบบบัญชี
    • ระบบการออกใบแจ้งหนี้
    • ระบบบัญชีรายจ่าย
    • ระบบลงลายเซ็น
    • สเปรดชีต (BI)
    • ESG
    การขาย
    • ลูกค้าสัมพันธ์
    • การขาย
    • ระบบสมัครสมาชิก
    • POS ร้านค้า
    • POS ร้านอาหาร
    • การเช่า
    การจัดการเว็บไซต์
    • เครื่องมือสร้างเว็บไซต์
    • อีคอมเมิร์ซ
    • ระบบการจัดงานอีเวนต์
    • บล็อก
    • ระบบการอบรมออนไลน์
    • ฟอรั่ม
    ซัพพลายเชน
    • คลังสินค้า
    • ระบบการผลิต
    • การซ่อมบำรุง
    • PLM
    • ระบบจัดการคุณภาพ
    • ระบบการจัดซื้อ
    ทรัพยากรบุคคล
    • ข้อมูลพนักงาน
    • การจ่ายเงินเดือนผ่านธนาคาร
    • ระบบสรรหาบุคลากร
    • ระบบการลา
    • การประเมิน
    • ระบบจัดการยานพาหนะ
    การตลาด
    • โซเชียลมาร์เก็ตติ้ง
    • การตลาดผ่านอีเมล
    • ระบบส่ง SMS
    • ระบบการตลาดอัตโนมัติ
    • WhatsApp
    • ระบบแบบสำรวจ
    การบริการ
    • โปรเจกต์
    • ระบบบันทึกเวลา
    • การวางแผน
    • การนัดหมาย
    • ไลฟ์แชท
    • ระบบดูแลช่วยเหลือ
    ประสิทธิผล
    • ปัญญาประดิษฐ์ (AI)
    • ระบบแสดงความคิดเห็น
    • VoIP
    • ไอโอที
    • เอกสาร
    • คลังข้อมูล
    แอปพลิเคชันของบุคคลที่สาม Odoo สตูดิโอ แพลตฟอร์มคลาวด์ของ Odoo
  • อุตสาหกรรม
    การค้าปลีก
    • ร้านขายหนังสือ
    • ร้านขายเสื้อผ้า
    • ร้านขายเฟอร์นิเจอร์
    • ร้านขายของชำ
    • ร้านขายวัสดุก่อสร้าง
    • ร้านขายของเล่น
    อาหาร & การบริการ
    • บาร์และผับ
    • ร้านอาหาร
    • อาหารฟาสต์ฟู้ด
    • เกสต์เฮ้าส์
    • ตัวแทนจำหน่ายเครื่องดื่ม
    • โรงแรม
    อสังหาริมทรัพย์
    • บริษัทอสังหาริมทรัพย์
    • บริษัทสถาปัตยกรรม
    • บริษัทรับเหมา
    • บริษัทจัดการทรัพย์สิน
    • การจัดสวน
    • สมาคมเจ้าของอสังหาริมทรัพย์
    ปรึกษา
    • สำนักงานบัญชี
    • Odoo พาร์ทเนอร์
    • เอเจนซี่การตลาด
    • สำนักงานกฎหมาย
    • บริการสรรหาบุคลากร
    • การตรวจสอบและการรับรอง
    ระบบการผลิต
    • สิ่งทอ
    • เหล็ก
    • เฟอร์นิเจอร์
    • อาหาร
    • โรงผลิตเบียร์
    • ของขวัญขององค์กร
    สุขภาพ & ฟิตเนส
    • ชมรมกีฬา
    • ร้านขายแว่นตา
    • ฟิตเนส
    • ผู้ประกอบวิชาชีพด้านสุขภาพ
    • ร้านขายยา
    • ร้านทำผม
    Trades
    • ช่างซ่อม
    • ฮาร์ดแวร์และการสนับสนุนด้านไอที
    • ระบบพลังงานแสงอาทิตย์
    • Electronic Store
    • บริการทำความสะอาด
    • บริการระบบปรับอากาศและระบายอากาศ
    อื่น ๆ
    • องค์กรไม่แสวงหากำไร
    • สำนักงานสิ่งแวดล้อม
    • ร้านเช่าป้ายโฆษณา
    • การถ่ายภาพ
    • ร้านเช่าจักรยาน
    • ตัวแทนจำหน่ายซอฟต์แวร์
    ดูอุตสาหกรรมทั้งหมด ⟶
  • คอมมูนิตี้
    ศึกษา
    • บทเรียน
    • เอกสารกำกับโปรแกรม
    • การรับรอง
    • การฝึกอบรม
    • บล็อก
    • พอดแคสต์
    เพิ่มศักยภาพให้กับการศึกษา
    • โปรแกรมการศึกษา
    • Scale Up! Business Game
    • เยี่ยมชม Odoo
    รับซอฟต์แวร์
    • ดาวน์โหลด
    • เปรียบเทียบรุ่น
    • ข้อมูลการอัปเดต
    ทำงานร่วมกัน
    • Github
    • ฟอรั่ม
    • ระบบการจัดงานอีเวนต์
    • การแปล
    • ร่วมเป็นพาร์ทเนอร์
    • บริการสำหรับพาร์ทเนอร์
    • ลงทะเบียนเพื่อสร้างบัญชีบริษัทของคุณ
    • Affiliate Program
    รับบริการ
    • ค้นหาพาร์ทเนอร์
    • ค้นหานักบัญชี
    • พบกับที่ปรึกษา
    • บริการติดตั้งระบบเพื่อใช้งาน
    • ข้อมูลอ้างอิงลูกค้า
    • การสนับสนุน
    • อัปเกรด
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    รับการสาธิต
  • ราคา
  • ช่วยเหลือ

ความปลอดภัย ของ Odoo

Security is a core part of how we design, operate, and maintain Odoo. This page summarizes the security practices and safeguards we apply to Odoo Cloud and the Odoo software.

— Odoo Cloud (แพลตฟอร์ม) —

CSA STAR Level 1

Odoo ได้เข้าร่วมในโปรแกรม CSA Security Trust Assurance and Risk (STAR)
ดูคำตอบสำหรับแบบสอบถาม CAIQv3.1 ของเรา

การสำรองข้อมูล / กู้คืนระบบ

  • We maintain a history of 14 full backups of each Odoo database for at least 3 months: daily backups for 7 days, weekly backups for 4 weeks, and monthly backups for 3 months.
  • Backups replicated in at least 3 different data centers.
  • สถานที่จริงของศูนย์ข้อมูลของเราระบุไว้ใน นโยบายความเป็นส่วนตัว.
  • คุณสามารถดาวน์โหลดข้อมูลสำรองด้วยตนเองได้ตลอดเวลาโดยใช้แผงควบคุม
  • You can contact our Helpdesk to restore an available backup to your live database or to a separate database.
  • ระบบสำรองฮาร์ดแวร์: สำหรับบริการที่โฮสต์บนเครื่องเซิร์ฟเวอร์จริง ซึ่งมีโอกาสที่ฮาร์ดแวร์จะเสีย เราได้ใช้การจำลองข้อมูลแบบสแตนด์บายในเครื่อง พร้อมระบบมอนิเตอร์และขั้นตอนสลับระบบสำรองแบบแมนนวล
  • Disaster recovery: we maintain disaster recovery procedures designed to restore Odoo Cloud services and customer data following major infrastructure failures or disasters. See our Cloud Service Level Agreement for more details and detailed Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO).

ความปลอดภัยของฐานข้อมูล

  • Customer data is stored in a dedicated database and is not shared between customers.
  • Data access controls isolate customer databases running on the same cluster, preventing access from one customer database to another.

การรักษาความปลอดภัยด้วยรหัสผ่าน

  • Customer passwords are protected using industry-standard PBKDF2+SHA512 password hashing, with salting and key stretching over thousands of rounds.
  • Odoo staff cannot access or retrieve your password. If a password is lost, it must be reset.
  • ข้อมูลรับรองการเข้าสู่ระบบจะถูกส่งผ่าน HTTPS ที่ปลอดภัยเสมอ
  • Customer database administrators can กำหนดค่าการจำกัดอัตรา and cooldown periods for repeated login attempts.
  • Password policies: database administrators can enforce a minimum user password length. Other policies, such as required character classes, are not enabled by default because research has shown them to be counterproductive. See [Shay et al. 2016] and NIST SP 800-63b.

การเข้าถึงของพนักงาน

  • Odoo Helpdesk staff may access your account when necessary to investigate a support issue. They use dedicated staff credentials rather than your password, which they cannot access.
  • Dedicated staff access allows our teams to reproduce reported issues without requiring you to share your password, while enabling staff actions to be separately controlled and audited.
  • Helpdesk staff limit their access to the data, files, and settings necessary to diagnose and resolve your issue.

ความปลอดภัยของระบบ

  • เซิร์ฟเวอร์ Odoo Cloud ทั้งหมดกำลังเรียกใช้การกระจาย Linux ที่เสริมประสิทธิภาพด้วยแพตช์ที่อัปเดตล่าสุดและมีความปลอดภัย
  • Server installations are purpose-built and minimal, reducing the number of services that could introduce vulnerabilities.
  • Remote server administration is restricted to a small number of trusted Odoo engineers and protected with personal multi-factor credentials.

ความปลอดภัยเชิงกายภาพ

Odoo Cloud servers are hosted in trusted data centers across multiple regions. All hosting facilities must meet our physical security requirements, including:

  • Restricted perimeters accessible only to authorized data center personnel.
  • Physical access controls using security badges or biometric authentication.
  • 24/7 security camera monitoring of data center facilities.
  • 24/7 on-site security personnel.

ความปลอดภัยของบัตรเครดิต

  • We do not store credit card information on our systems.
  • Credit card information is transmitted securely and directly to เป็นไปตามมาตรฐาน PCI payment acquirers. See our นโยบายความเป็นส่วนตัว for the list of providers.

การเข้ารหัสข้อมูล

Customer data is encrypted both in transit and at rest.
  • Communications with customer instances are protected using HTTPS with 256-bit SSL encryption.
  • Internal communications between servers are protected with end-to-end encryption.
  • Our servers are continuously monitored and kept up to date with patches for SSL vulnerabilities.
  • Our SSL certificates use 2048-bit keys with full SHA-2 certificate chains. You can verify the SSL rating ที่นี่.
  • Customer data, including database contents and stored files, is encrypted at rest with AES-256 in both production systems and backups.

เครือข่าย  การป้องกัน

  • Data centers providers used for Odoo Cloud operate high-capacity networks designed to withstand large volumes inluding most Denial of Service attacks. Automated and manual mitigation systems detect and divert attack traffic at the network edge before it can disrupt service availability.
  • ไฟร์วอลล์และระบบป้องกันการบุกรุกบนเซิร์ฟเวอร์ Odoo Cloud ช่วยตรวจจับและบล็อกภัยคุกคามต่างๆ เช่น การโจมตีด้วยรหัสผ่านแบบบังคับที่มีจุดประสงค์ร้าย
  • Customer database administrators can กำหนดค่าการจำกัดอัตรา and cooldown duration for repeated login attempts or configure a CAPTCHA to mitigate automated brute-force attacks.

— Odoo (ซอฟแวร์) —

ความปลอดภัยของซอฟต์แวร์

Odoo is open source, allowing its codebase to be continuously reviewed by users and contributors worldwide. Community reports are an important source of security feedback, and we encourage developers and security researchers to audit the code and report security issues.

Odoo R&D processes include code reviews that consider security aspects for both new and contributed code.

ออกแบบมาเพื่อความปลอดภัย

The Odoo framework is designed to prevent common classes of security vulnerabilities by default:

  • SQL injection is prevented by a higher-level API that generally removes the need for manually constructed SQL queries.
  • Cross-site scripting (XSS) is prevented by a high-level templating system that automatically escapes injected data.
  • The framework prevents RPC access to private methods, reducing the risk of exposing exploitable functionality.

See the ช่องโหว่อันดับต้นๆ ของ OWASP section for more information about the protections built into the Odoo framework.

การตรวจสอบความปลอดภัยแบบอิสระ

Odoo is regularly assessed by independent security companies engaged by our customers and prospects to conduct security audits and penetration tests. The Odoo Security Team reviews the findings and implements corrective measures where necessary.

We cannot disclose these assessment reports because they are confidential and belong to the organizations that commissioned them.

Odoo also works with an active community of independent security researchers who review our source code and help us continuously improve its security. Our security research and disclosure process is described on our การเปิดเผยข้อมูลอย่างมีความรับผิดชอบ หน้า

ช่องโหว่อันดับต้นๆ ของ OWASP

The following summarizes how Odoo addresses common web application security risks identified by the Open Web Application Security Project (OWASP):

  • Injection Flaws: Injection flaws occur when untrusted data is passed to an interpreter as part of a command or query, potentially causing unintended commands to be executed or data to be modified.

    Odoo relies on an object-relational mapping (ORM) framework that abstracts query construction and prevents SQL injection by default. Developers do not normally need to construct SQL queries manually: queries are generated by the ORM and parameters are properly escaped.

  • Cross-Site Scripting (XSS): XSS vulnerabilities occur when untrusted content is included in a web page without appropriate escaping or encoding, potentially allowing an attacker to execute scripts in another user's browser.

    The Odoo framework escapes expressions rendered into views and pages by default, preventing XSS in normal usage. Developers must explicitly mark expressions as safe before they can be included as raw content in rendered pages.

  • Cross-Site Request Forgery (CSRF): A CSRF attack attempts to make an authenticated user's browser submit an unauthorized request to a web application using the user's existing session.

    The Odoo website engine includes built-in CSRF protection. HTTP controllers do not accept protected POST requests without the corresponding security token. The token is provided when the user legitimately accesses the relevant form and cannot be forged by an attacker.

  • Malicious File Execution: Remote file inclusion vulnerabilities can allow an attacker to load and execute hostile code or data on a server.

    Odoo does not expose functionality for remote file inclusion. Privileged users can customize certain features using expressions evaluated by the system, but these expressions run in a sandboxed and sanitized environment with access limited to permitted functions.

  • Insecure Direct Object Reference: Direct object references expose identifiers for internal objects, such as records or files. They become a vulnerability when manipulating those identifiers allows unauthorized access.

    Odoo access control is enforced independently of the user interface. Exposing references to internal objects in URLs therefore does not bypass authorization: every request must still pass through the data access validation layer.

  • Insecure Cryptographic Storage: Weak protection of stored credentials or sensitive data can expose users to unauthorized access, identity theft, and other forms of abuse.

    Odoo uses industry-standard secure password hashing (PBKDF2 + SHA-512 with key stretching by default) to protect stored user passwords. External authentication systems such as OIDC/OAuth can also be used to avoid storing user passwords locally.

  • Insecure Communications: Sensitive information may be exposed when applications fail to appropriately encrypt network communications.

    Odoo Cloud enforces HTTPS by default. For on-premise installations, we recommend running Odoo behind a web server that provides encryption and proxies requests to Odoo, such as Apache, Lighttpd, or nginx. The Odoo deployment guide includes a รายการตรวจสอบความปลอดภัย for securing public deployments.

  • Failure to Restrict URL Access: Applications may expose sensitive functionality when authorization is enforced only by hiding links or URLs from unauthorized users.

    Odoo does not rely on the user interface or hidden URLs for access control. Every request must pass through the data access validation layer, so manipulating or directly accessing a URL does not bypass authorization. Where a URL intentionally provides unauthenticated access to sensitive information, such as a customer order confirmation link, the URL is protected with a unique digitally signed token and sent only to the intended recipient.

รายงานความเสี่ยงด้านความปลอดภัย

To report a security vulnerability, please use our หน้าการเปิดเผยข้อมูลอย่างรับผิดชอบ. Security reports are treated with high priority and assessed by the Odoo Security Team. We work with reporters to investigate and remediate confirmed issues and, where appropriate, disclose them responsibly to Odoo customers and users.

— Odoo Cloud (แพลตฟอร์ม) —การสำรองข้อมูล / กู้คืนระบบความปลอดภัยของฐานข้อมูลการรักษาความปลอดภัยด้วยรหัสผ่านการเข้าถึงของพนักงานความปลอดภัยของระบบความปลอดภัยเชิงกายภาพความปลอดภัยของบัตรเครดิตการเข้ารหัสข้อมูลเครือข่าย  การป้องกัน— Odoo (ซอฟแวร์) —ความปลอดภัยของซอฟต์แวร์ออกแบบมาเพื่อความปลอดภัยการตรวจสอบความปลอดภัยแบบอิสระช่องโหว่อันดับต้นๆ ของ OWASPรายงานความเสี่ยงด้านความปลอดภัย
คอมมูนิตี้
  • บทเรียน
  • เอกสารกำกับโปรแกรม
  • ฟอรั่ม
โอเพนซอร์ส
  • ดาวน์โหลด
  • Github
  • Runbot
  • การแปล
บริการ
  • โฮสติ้ง odoo.sh เซิร์ฟเวอร์
  • การสนับสนุน
  • อัปเกรด
  • การพัฒนาที่กำหนดเอง
  • การศึกษา
  • ค้นหานักบัญชี
  • ค้นหาพาร์ทเนอร์
  • ร่วมเป็นพาร์ทเนอร์
เกี่ยวกับเรา
  • บริษัทของเรา
  • ทรัพย์สินในรูปของเครื่องหมายการค้า
  • ติดต่อเรา
  • งาน
  • ระบบการจัดงานอีเวนต์
  • พอดแคสต์
  • บล็อก
  • ลูกค้า
  • กฎหมาย • ความเป็นส่วนตัว
  • ความปลอดภัย
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) Português română русский язык Slovenský jazyk Slovenščina Español (América Latina) Español Svenska ภาษาไทย Türkçe українська Tiếng Việt

Odoo เป็นชุดแอปธุรกิจแบบเปิดที่ครอบคลุมทุกความต้องการของบริษัทของคุณ อาธิ CRM อีคอมเมิร์ซ ระบบบัญชี ระบบคลังสินค้า ระบบการขายหน้าร้าน โปรเจกต์ และ อีกมากมาย

ความเหนือกว่าอันเป็นเอกลักษณ์ของ Odoo คือการใช้งานที่ง่ายดายและผสานการทำงานอย่างสมบูรณ์แบบในเวลาเดียวกัน

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now