Security at OmniStrat.
The product's entire premise is that you should not have to trust us. That principle runs through the security design: wherever possible, a control is something you can verify yourself rather than a promise we ask you to believe. This page is what a procurement or compliance team needs before a call.
Encryption
Sensitive fields are encrypted at rest with column-level encryption, so a database compromise does not hand over plaintext. In transit, everything runs over TLS on Cloudflare's network.
The strongest case is broker credentials in the Terminal. Those are encrypted client-side, in your browser, with AES-GCM-256 using a key derived from your Vault passphrase via PBKDF2-SHA256 at 250,000 iterations. Only the ciphertext, salt, and initialisation vector are ever sent to us. The plaintext key never leaves your device, which means that even under subpoena we can produce only ciphertext — useless without a passphrase we never hold.
The audit log is verifiable, not just retained
Every attestation, decision receipt, cohort event, and order record is signed with Ed25519 and written into an append-only, hash-chained log. Each entry commits to the one before it, so removing, editing, or reordering any entry breaks every entry after it — detectably, by arithmetic anyone can run.
The practical consequence is that a regulator, an auditor, or a counterparty does not have to trust our change-management controls or take our export on faith. They re-hash the payload, check the signature against the public key, and confirm the chain position, in a browser, at omnistrat.ai/verify, with no account. Evidence that depends on the vendor's honesty is not evidence; this does not.
Access and identity
- Least-privilege access internally.
- MFA on every administrative surface.
- Per-org data residency and tenant isolation — an entitlement proves a caller may act somewhere, never on another org's records.
- Bring Your Own Keys (BYOK) for AI providers: your provider keys are encrypted at rest with your Vault passphrase, and we never see plaintext. The model spend lands on your provider account, not ours.
Data handling
- We do not sell, share, or trade your data. No ad networks, no ad pixels, no fingerprinting analytics.
- Deletion: personal data is erased within 30 days of an account-deletion request (backup rotation window). Exercise it in-app from your Passport, or via the API.
- Retention: audit-chain records are held for the security-audit window unless a legal hold applies.
- Records archive: the Terminal compliance workstation writes to a 17a-4-style WORM archive, chain-anchored to the same substrate.
Certifications — the honest status
We would rather state this plainly than imply a badge we have not earned.
SOC 2: not yet certified. OmniStrat is built to SOC 2 control objectives — the encryption, audit log, least-privilege access, MFA, and residency above are those controls. The underlying infrastructure (Cloudflare) is itself SOC 2 Type II certified, which covers the platform and physical layer but not our application controls. A SOC 2 Type II report requires an independent auditor over an observation window, and we have not completed that engagement.
HIPAA: the same picture. The technical safeguards are in place and we can execute a BAA, but there is no third-party HIPAA attestation behind it yet.
If your procurement process requires a completed SOC 2 report today, we will tell you up front rather than waste your time. For everything short of that, email enterprise@omnistrat.ai and we will walk you through the control set, the architecture, and the audit-chain verification you can run yourself.
Reporting a vulnerability
Found something? Email security@omnistrat.ai with steps to reproduce. We read every report and will not pursue good-faith researchers who follow responsible disclosure.
Frequently asked
Is OmniStrat SOC 2 certified?
Not yet, and we say so rather than imply otherwise. OmniStrat is built to SOC 2 control objectives — column-level encryption at rest, an append-only hash-chained audit log, least-privilege access, MFA on every administrative surface, and per-org data residency. The underlying infrastructure, Cloudflare, is itself SOC 2 Type II certified, which covers the platform layer but not our application controls. A SOC 2 Type II report requires an independent auditor over an observation window, and we have not completed that engagement. If you need the report today, we will tell you up front rather than waste your time.
Can you sign a HIPAA BAA?
The technical safeguards are in place and we can execute a BAA, but there is no third-party HIPAA attestation behind it yet. Same posture as SOC 2: the controls exist, the independent report does not.
How are broker and provider keys stored?
Broker keys used by the Terminal are encrypted client-side with AES-GCM-256 using a key derived from your Vault passphrase via PBKDF2-SHA256 at 250,000 iterations. Only the ciphertext, salt and IV reach the server; the plaintext key never leaves your device. Under subpoena we can hand over only ciphertext, useless without your passphrase.
Can a regulator verify our records without trusting OmniStrat?
Yes. Every attestation, decision receipt, and order record is Ed25519-signed and written into an append-only hash chain. A third party re-hashes the payload, checks the signature against the public key, and confirms the chain position, at omnistrat.ai/verify.html, with no account and no cooperation from us.
Email enterprise@omnistrat.ai for the control set and architecture walk-through, or verify a live record yourself first.
Verify a record →