Back to home

Security at Omniscient

How we protect your most personal data

AES-256 Encryption at Rest

Every memory, conversation, and personal data point is encrypted at rest using AES-256-GCM. Each user's data uses a unique encryption key. Your data is mathematically unreadable without your key.

TLS 1.3 in Transit

All data moving between your device and Omniscient servers is encrypted with TLS 1.3. Older protocol versions are explicitly disabled. We enforce HSTS headers on all endpoints.

Zero Training on Your Data

Your personal memories, conversations, and context are never used to train AI models. We use inference-only — your data improves your AI, not anyone else's. This is legally binding in our terms.

OAuth-Only Integrations

We never ask for or store your passwords to third-party services. All integrations use OAuth 2.0 with minimal permission scopes. You can revoke any connection at any time.

Privacy by Design

Omniscient collects only what it needs. You control who sees what with per-memory privacy settings. You can delete everything — instantly — with a single click.

Privacy-Respecting Analytics

INT-01

We use Plausible Analytics — a privacy-first analytics tool that collects zero personal data, no cookies, no fingerprinting, no IP storage. We track only aggregate page views and feature usage to improve the product. Your identity is never part of any analytics event.

Dependency Security Scanning

SEC-18

Every dependency in the Omniscient codebase is continuously scanned for known vulnerabilities using automated tools. Our CI/CD pipeline blocks any deployment that introduces a high-severity vulnerability.

Dependabot alertsnpm audit on every PRSocket.dev scanningWeekly dependency review

SOC 2 Compliance Roadmap

SEC-17

We are actively working toward SOC 2 Type II certification. Our infrastructure and processes are being aligned with the Trust Services Criteria.

Security controls documented✓ Complete
Access management policies in place✓ Complete
Audit logging on all AI data access✓ Complete
Incident response procedures✓ Complete
Third-party penetration test⟳ In progress
SOC 2 Type I auditPlanned
SOC 2 Type II certificationPlanned

Your data is safe with us

Questions? Reach us at security@omniscient.ai