Omi Health Trust Center

Security, privacy and compliance.

How Omi protects clinical data, where it is processed, which agreements are available, and the current status of external assurance.

Last reviewed 10 August 2026
EU processingCustomer content stays in AWS eu-central-1.
BAA & DPASelf-serve in the console on every tier.
1–72 hour retentionConfigurable result expiry; audio deleted after processing.
No model trainingCustomer content is never used to train Omi models.
Assurance status

What is available today.

Certification status is shown as complete only after independent verification.

Request the security pack →
Available

HIPAA / BAA

Execute the published BAA in the console before sending PHI. The API uses HIPAA-eligible AWS services in the PHI path.

A BAA is a contract, not a certification.
Available

GDPR / DPA

GDPR Article 28 DPA, EU processing, SCCs and region-specific privacy addenda are published.

Omi Health B.V. is established in the Netherlands.
Planned

SOC 2 Type II

Not currently certified. Auditor engagement is the next external-assurance milestone.

We will publish status only after the engagement begins.
Evaluating

ISO/IEC 27001

Not currently certified. Formal certification is being evaluated after the SOC 2 workstream.

No ISO certification is claimed today.
Data flow

One visible processing boundary.

This scope describes the hosted Speech-to-Text Developer API. Open-model and customer-managed deployments run inside the environment you control.

1 · CustomerYour application

Sends audio over TLS using an account-scoped API key.

2 · European UnionOmi API · AWS Frankfurt

Transcription and customer-content processing remain in eu-central-1.

3 · CustomerYour transcript

Audio is deleted after processing; async results follow your selected expiry.

i

Identity is separate. Console authentication runs in Azure Sweden Central and processes account and authentication data—not audio, transcripts or PHI. Cloudflare serves the website and DNS; customer API content does not transit the website CDN.

Implemented controls

Security in the product.

Concrete controls from the production technical and organisational measures.

01

Encryption

TLS for external traffic. Customer-content stores use AWS KMS customer-managed keys with rotation.

02

Credential handling

API keys are shown once and stored as SHA-256 hashes. Service secrets live in AWS Secrets Manager.

03

Least privilege

Role-based access, scoped IAM and no standing human access to customer content.

04

Immutable audit

Content-free security and compliance events are written to KMS-protected, Object-Locked storage.

05

Tenant isolation

Keys, jobs, results and vocabulary are account-scoped, with authorization on every retrieval.

06

Data minimisation

Customer content is excluded from operational logs and backups; deletion is enforced independently.

Need evidence for your review?

Request the enterprise security pack, report a security concern, or check current service health.