Omnox

Security

What's actually true about how Omnox is built, not a compliance mad-lib.

Last updated July 22, 2026

This is a draft written to be honest about what this site actually does, not a substitute for legal advice, pending final review by outside counsel. Have it checked before relying on it for compliance or real client contracts.

Omnox is a beta product built by a very small team. This page says what's real today, what's in progress, and what isn't built yet. That's on purpose, instead of a generic trust page that reads the same for every vendor. If you're evaluating Omnox for your team and something below isn't enough, ask us directly at hello@omnox.ai. We'd rather have that conversation than let a page paper over a gap.

Authentication

Tenant isolation

Every record in the CRM is scoped to a tenant ID, enforced at the data-access layer on every read and write. One customer's data is never visible to another customer's account. Requests without a valid session are rejected outright (HTTP 401) rather than falling back to a shared or default account.

Data in transit and at rest

File uploads

Document ingest (contract/deal extraction) enforces a file-size cap and a file-type allowlist before anything is processed. Uploaded files are processed in memory and sent to our AI provider for extraction; they are not written to disk or made visible to any other tenant.

AI features

Omnox's AI features run on Anthropic's Claude API. See our AI Governance Statement for what data is sent, what isn't, and how AI outputs should (and shouldn't) be relied on.

What we don't have yet

Said plainly, because a vendor security review will ask anyway:

None of that is hidden in fine print. It's the honest state of a beta product, and it's why Omnox is priced and positioned the way it is today. If your organization needs one of the above in place before you can use Omnox, tell us. It changes our roadmap priorities, not just our messaging.

Reporting a vulnerability

Found a security issue? Email hello@omnox.ai with details and we'll respond as quickly as we can. Please don't publicly disclose before we've had a chance to fix it. We'll credit you if you'd like once it's resolved.

Changes

This page will change as the product does. We'd rather update it and have it be true than leave a stale claim standing.