Skip to content
Omni Workforce

Security & trust

You're handing us the inbox.

So here is exactly where your data goes, who can reach it, and what an employee is allowed to do without asking.

Your data is not our training data

The single question every owner asks first. The answer is no, and it is in the contract rather than the marketing.

  • Your business data and your customers' data are never used to train general-purpose models
  • Our model providers are under agreements that prohibit training on data we send them
  • We do not sell personal data, and we do not share it for advertising
  • For the data your employees touch, you are the controller and Omni is the processor — we act on your instructions

How it is stored

One customer's data is unreachable from another customer's account, enforced at the database level rather than in application code.

  • Encrypted in transit (TLS) and at rest
  • Row-level security on every table, scoped to your organization
  • Least-privilege access for Omni staff, and only where the work requires it
  • Payment card details are handled entirely by Stripe — we never see or store them

What an employee can and cannot do

Autonomy has a defined edge. The limits are set per role, and you set them.

  • Every role has an escalation line — irreversible actions route to a person on your side
  • An employee only reaches the tools you connect, and only the scopes you grant
  • Nothing is sent in your name that you have not approved the pattern for
  • You can pause any employee immediately from your dashboard

When something goes wrong

Say what happened, say what we did, say what happens next — in that order.

  • We stop the affected work first, then tell you
  • You get the list of what was affected, not a summary
  • Breaches affecting personal data are disclosed to you directly
  • No incident report from us will ever open with the word 'unfortunately'

Access and deletion

Your data stays yours, including on the way out.

  • Export your data at any time, and for thirty days after you leave
  • Deleted ninety days after termination, except financial records law requires us to keep
  • Request access, correction or deletion of personal data at any time — it will never cost you service quality

What we don’t have yet

The certifications we haven’t earned.

Most security pages imply more than they hold. Ours says where we actually are, because you will find out at the technical review anyway.

  • SOC 2

    Not yet

    We are a young company and have not completed an audit. We will say so here the day we do, and not before.

  • Data processing agreement

    On request

    Email us and we will send one. Standard Contractual Clauses cover transfers out of the EEA and UK.

  • Penetration testing

    Not yet

    Planned before we take on customers handling regulated data.

Reporting a problem

Found something? Tell us.

Email info@omniwfm.ai with what you found and how to reproduce it. We will confirm receipt within one business day and tell you what we are doing about it. We will not threaten anyone who reports a vulnerability in good faith.

Our privacy policy covers what we collect and why. A data processing agreement is available on request.

Let’s build it

Bring your compliance questions.

Twenty minutes. If we cannot meet a requirement you have, we will say so on the call rather than after the contract.