Skip to content

Security & Trust

What we can prove, and what we are still proving.

This page is for IT, legal, procurement and risk. Where evidence exists, it is named. Where work remains, the status says so instead of displaying a badge nobody checked.

Security & Trust · Data stays in the European Union · Availability is measured, not advertised · AI follows the same controls

Best fit
IT, legal, procurement, risk and data-protection teams
Operational job
Verify controls, scope, documents and open evidence before rollout.
What you get
A review of available controls, documents and items that still need verification.

System relationship

Security & Trust across the connected product system

The same identity, permission and audit rules travel through the core record, AI assistance, integrations and every product workflow.

Security & Trust

DMS Core
BRAIN
Open Platform
Product workflows

How the platform is protected

Six controls, described plainly enough to check

Each statement names something a reviewer can ask the team to demonstrate in the customer's own environment.

Data protection

Encryption in transit and at rest. Encrypted backups are restore-tested on a schedule, with evidence available on request.

Privacy and GDPR

Omnetic acts as processor for customer data. The DPA, processing records, retention, erasure and data-subject requests follow the contract.

Access controls

Role- and site-scoped staff access, SSO where used and MFA for administrators. Support access is least-privilege, time-bound and logged.

Auditability

Record changes store the user, timestamp and previous value. Integration calls and AI approvals share the exportable trail.

Availability and resilience

Redundant infrastructure, an incident process and documented recovery objectives. RTO and RPO values remain pending sign-off and are not advertised here.

Responsible AI

Autonomy is set per action and role; commercial steps require human approval and inputs and outcomes are logged. Provider and subprocessor publication remains pending.

Compliance and certification

No badge appears until the evidence does

A certification mark is a claim about one entity and one scope. Reserved slots do not become standard names or logos.

In force

GDPR processor terms

A DPA is issued with each contract, including standard contractual clauses where a transfer applies.

In force

EU data residency

Production data and backups are hosted in EU regions named in the contract. External support access requires an approved, logged exception.

Locked slot

Information-security certification

No mark, standard name or scope is published until the certificate and covered entity are confirmed in writing.

Locked slot

Independent assurance report

Reserved for a completed report that can be shared under NDA. It does not imply an audit has already taken place.

Trust centre

Documents, and how to get them

Some documents are public, some are released on request or under NDA, and some are not ready. A request for an in-preparation item should return a date, not a maybe.

Request a document

Public · available

Data processing agreement

Processor terms and applicable transfer clauses.

We use the details you provide to handle this request and contact you about it. Privacy policy.

Incidents and contact

When something goes wrong, you hear it from us

Availability history belongs on the status page. Security-relevant incidents are notified to affected customers under contractual timelines, not hidden in a release note.

Status page

Current state per service and a rolling incident history. The SLA figure lives in the contract, not in marketing.

Request status history

Security questionnaire

Send your own template. The team completes it instead of insisting a buyer accepts ours.

Send a questionnaire

Vulnerability reports

security@omnetic.com. The source states acknowledgement within one working day and a named owner.

Reporting guidelines

Start the security review early

Most delays come from a questionnaire that arrived after the rollout plan. Send it while the pilot is being scoped.

Talk to security
  1. Scope

    Entities, markets, data categories and integrations in review.

  2. Documents

    What must be public, on request or under NDA.

  3. Questionnaire

    The buyer's own control and evidence format.