Secure cloud analytics

Built by a team with years of experience — we know how to keep your data secure.

Free Trial
SOC 2
ISO/IEC 27001
HIPAA
GDPR
CCPA

Platform security

Our platform is designed to prioritize the security of customer data. Encryption and isolation are used to keep data and credentials secure, and systems are strictly access-controlled on the basis of least privilege. Penetration testing and vulnerability scanning are used to proactively identify and close vulnerabilities.

Organization security

Our hiring and training processes emphasize data security as our most important job.

Our security program implements rigorous controls to protect customer data, including personnel background checks and regular security training.

Compliance

Omni is ISO/IEC 27001:2022 certified, completes annual SOC 2 Type II audits, and is independently audited for HIPAA compliance. We also meet the standards of the GDPR and CCPA.

Modern analytics with robust security features

Governed data model

  • Control access to data on the view (table) and field (column) level

  • Row-based filtering based on user permissions

  • Model change management

Powerful security administration

  • Granular permission roles

  • Permissions on the user and group level

  • User attribute-based access control for flexible data permissions

  • SAML & SCIM

Secure data connectivity and processing

  • Data connections are encrypted

  • Tunneled and PrivateLink connections to securely access data in private networks — AWS, Azure, Snowflake, Redshift, and Databricks

  • Data stays encrypted inside the Omni platform

One secure platform for all your data needs

2User’s BrowserCustomer’s DataWarehouse1Auth Service3Network connectionfrom Omni to datawarehouse

Learn more about our security practices

Data & infrastructure security

Infrastructure provider

Omni's platform is securely hosted on Amazon Web Services (AWS) and Microsoft Azure, in data centers with on-site security personnel, extensive camera surveillance, and a suite of other security controls. Deployment is supported in specific regions per cloud provider — the US, Canada, the EU, Australia, and India on AWS, and the US, the UK, and Australia on Azure. See the full list of supported cloud regions in our docs.

Data encryption

All customer data stored on Omni is encrypted using the industry-standard AES-256 encryption protocol. Data in transit to or from Omni's services is safeguarded using TLS or equivalent encryption technologies, ensuring end-to-end data protection. Database credentials are protected with an additional layer of application-level encryption and can only be decrypted by the components that require them.

Customer data handling

Customer data is never copied outside of Omni's production infrastructure and is never used for testing, development, or any purpose beyond delivering the product. Data is stored in Omni systems only temporarily and can be permanently deleted upon request. Learn more about our information security program in our docs.

Tenant isolation

Customer data is logically segregated by tenant, and authentication and authorization checks are applied to every incoming request. Request sandboxing ensures each request is isolated to the appropriate user and organization. Learn more about our product security and architecture in our docs.

Access control

User access is managed through centralized authentication and provisioning and rigorously enforced two-factor authentication (2FA). Our approach ensures that only authorized personnel can access sensitive information, bolstering our defense against unauthorized access.

Network security & system monitoring

Omni maintains stringent control over access to critical data and systems. Every access event is logged and our systems are continuously monitored. Any unusual activity is promptly identified and addressed.

Support access

Access by Omni personnel to your Omni instance is always visible to you, and is controlled — and can be revoked — by you. Support access to customer data is granted only when you allow it.

Uptime & status

Omni publishes real-time availability and incident history on our status page and offers a 99.9% uptime SLA. Our on-call engineering team provides around-the-clock incident response.

AI security

AI model providers

Omni's AI features are powered by Anthropic's Claude models hosted on AWS Bedrock by default, and organizations can instead configure Anthropic Direct, Google Vertex AI, OpenAI, or Grok (xAI). Custom provider API keys are securely stored per organization and are never exposed in the UI after saving. Models are region-specific to ensure data privacy — EU-based users are served by EU-deployed models.

Your data & AI

Data provided to the LLMs used by Omni — including metadata — is never used for model training. Query generation shares only metadata, such as field names, filters, and topic names; no private, relational, or result set data is shared. AI-generated queries always respect your existing user permissions.

AI data retention

When summarizing results, query data is shared with the model but remains within AWS. Summary responses are retained for 30 days, and query results follow our standard cache policies. Learn more about AI security and privacy in our docs.

Personnel security

Formal security policy

Omni maintains a robust security culture, anchored by a comprehensive set of security policies. These policies are continually reviewed and updated to adapt to the evolving security landscape. All employees are provided with these materials as part of their training, ensuring that our team is well-versed in our security protocols and best practices.

Onboarding & offboarding process

The security of our operations begins with our people. Each new team member undergoes a thorough background check and signs a confidentiality agreement as a precondition of employment. Additionally, all employees are required to complete an annual security training course, reinforcing our commitment to maintaining a vigilant and informed workforce.

We manage the access rights of departing employees meticulously. Using a centralized identity provider (IdP) we ensure immediate and comprehensive revocation of access to company devices and applications.

Development

Penetration testing

To proactively identify and address potential vulnerabilities, Omni engages in regular penetration testing conducted by reputable security firms.

Responsible disclosure

Omni runs a vulnerability disclosure program covering all Omni-operated systems under omni.co and omniapp.co. Security researchers can report vulnerabilities to security@omni.co — we acknowledge reports within 3 business days, work to fix confirmed issues quickly, and will not pursue legal action against researchers who follow the program's guidelines.

Application monitoring

Authentication activities are meticulously logged and audited. We employ a variety of tools to scrutinize the libraries used in our application for known vulnerabilities. Additionally, we consistently monitor the health and activity metrics of our production environment, ensuring robust performance and security at all times.

Change management

Our development process adheres to a rigorous Systems Development Life Cycle (SDLC), with a strong emphasis on security and efficiency. Utilizing GitHub, we ensure that every change to our system is thoroughly peer-reviewed and rigorously tested prior to deployment in our production environment.

Third-party vendor security

Omni extends our security principles to our network of third-party vendors. We have implemented a comprehensive process to ensure that all our sub-processors adhere to our stringent data protection and security standards.

Visit our Trust Center

Our Trust Center is the fastest way to review Omni's certifications and security documentation, and to request access to audit reports like our SOC 2 Type II and ISO/IEC 27001 reports. For anything else, contact your account team or email our security team directly.