Security & Trust
Omnia Voice operates a sovereign, OpenAI-compatible LLM gateway. Security is a design constraint, not an afterthought — here is how we protect your data, and where our compliance program stands.
Compliance
SOC 2 Type IIIn progress — audit preparation
ISO/IEC 27001In progress — certification track
GDPRProgram active
HIPAAFramework adopted
How we handle your data
- No content retention by default. Prompts and completions are processed in memory and are not persisted unless your workspace explicitly opts in to logging (with configurable 7/30/90-day retention and per-request opt-out).
- EU inference available. Model inference runs on infrastructure with EU data-residency options; inference providers are contractually barred from training foundation models on your data.
- Tenant isolation. Every request is scoped to your workspace; cross-tenant access fails closed.
- Encryption everywhere. TLS 1.2+ in transit; encryption at rest across all data stores. API keys are stored as salted hashes — plaintext keys are never persisted.
Security practices
- Tamper-evident, hash-chained audit logging of administrative and authentication events
- Two-factor authentication (TOTP) and role-based access control
- Per-workspace rate limiting and fail-closed billing controls
- CI/CD with mandatory code review, secret scanning, and dependency vulnerability management
- Independent penetration testing (scheduled as part of the SOC 2 program)
- Continuous compliance monitoring with automated evidence collection
Subprocessors
| Provider | Purpose | Region |
|---|---|---|
| Nebius B.V. | LLM inference (ISO 27001, SOC 2 Type II) | EU (Finland/France) |
| Neon | Managed PostgreSQL | EU |
| ClickHouse Cloud | Telemetry & audit storage | EU |
| Vercel | Application hosting & edge network | Global |
| Railway | Service hosting | EU/US |
| Upstash | Caching & rate limiting | EU |
| Stripe | Payment processing | Global |
| Resend | Transactional email | US |
| Identity & workspace | Global |
Contact & disclosure
Security questions, report a vulnerability, or request our security documentation: security@omnia-voice.com. We acknowledge disclosure reports within 72 hours.