Skip to content
Security & trust

Your data, handled like it's regulated

Omni sees how your organisation works: its workflows, systems, and data. That access is a responsibility we engineer for. Here is how we handle it.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest. Credentials and secrets are stored in managed secret stores, never in code or configuration files.

Least-privilege access

Omni connects to your systems with the narrowest access that does the job, read-only wherever possible, and every integration is scoped, logged, and revocable.

Data minimisation

We ingest what the analysis needs and no more. Where aggregates or metadata are sufficient, we don't take raw content. Your data is never used to train models.

Transparency by design

Visibility is the product: everything Omni touches, ingests, or produces is inspectable by your team. There is no black box between you and your own data.

Modern managed infrastructure

We run on reputable managed cloud infrastructure with provider-level physical security, network isolation, and automated patching.

Governance, practised on ourselves

We sell AI governance, so we hold ourselves to it: our own AI usage is documented, governed, and accounted for under the same discipline we bring to our customers.

Data residency and sovereignty

Valstra is Australian owned and operated. Your model and the material behind it stay in the region you nominate, and the region is part of the scoping conversation rather than an upgrade you negotiate for.

Bring your own key

Hold your own encryption keys, rotate them on your schedule, and revoke them without raising a support ticket. Set up with your security team as part of onboarding.

Recorded access, in a register you can take away

Touching sensitive material is an event: a source record read, a stored screenshot served, a model proposal applied, a connector granted. Each one is recorded with who, when and what it touched, filterable on screen and exportable as a file. A row never carries the value it describes, and exporting the register is itself recorded.

Your data leaves when you do

When an engagement ends, everything belonging to it leaves in one bundle and is then erased from every store it reached, including the attachments and screenshots held outside the main record. What goes into the export and what the erasure destroys are computed from the same definition, so the two can never be different lists, and both acts are recorded.

Recovery to a point in time

An engagement can be rolled back to an earlier version of itself without moving any other engagement, so recovering one customer never charges every other customer a day of their work. The state being replaced is archived first, which gives the recovery its own undo point.

Capture is consented, never background monitoring

Recording a process is something a person chooses to do once, for one task, with sensitive input masked. There is no administrator-configured, always-on capture of what staff do on their screens, and none is planned: the consented model is the point, not a limitation we are working around.

Questions about our security posture?

We're happy to walk your security, risk, or procurement team through our architecture, data handling, and controls in detail, including completing security questionnaires as part of an evaluation.