Security & privacy
~ $ omega audit --trust

Built so your
code never
leaves you

GDPR-native. EU-hosted. Never trained on. Here is the full audit — line by line.

1.3
TLS
edge to origin, end to end
0
training
we never train models on your code
24h
triage
on a reported vulnerability
30d
fix window
for anything critical
The guarantees

Six promises, no asterisks.

01

Your code stays yours

Held in memory for the duration of a request, and never used for training. The two features that must outlive a request — background agents and batch jobs — store their input for the job, then scrub it within 24 hours of it finishing.

02

EU-hosted by default

EU-region origin · global edge · GDPR-native subprocessor list.

03

Encryption everywhere

TLS 1.3 in transit, end to end. Encrypted from the edge to our origin.

04

Daily reconciliation

Every euro we charge reconciles against the provider invoice. Discrepancies surface in /stats.

05

No third-party trackers

No third-party ad or analytics trackers, no session-replay. Privacy-respecting, EU-hosted analytics only if you opt in; we honour Do-Not-Track.

06

BYOK supported

Drop in your own model-provider key. Omega routes through it. You pay the provider directly.

Compliance roadmap

Where the paperwork stands.

No vapourware badges. What is live, what is dated, what we will do if you ask.

GDPR
LiveNative. DPA template available.
CCPA
LiveNo sale of personal data. Opt-out form on request.
SOC 2 Type I
Planned Q3 2026Auditor engaged. Trust-portal goes live with the report.
SOC 2 Type II
Planned Q1 2027After 6-month observation window.
HIPAA BAA
On request (Enterprise)On request for Power + Enterprise.
ISO 27001
EvaluatingPending demand. Email if it blocks you.
Responsible disclosure

Found a vulnerability?

Email [email protected] with the details. Encryption key available on request. Triage in 24h, fix in 30 days for critical, public credit unless you'd rather we didn't.