Security, privacy and compliance.
How Omi protects clinical data, where it is processed, which agreements are available, and the current status of external assurance.
Last reviewed 10 August 2026What is available today.
Certification status is shown as complete only after independent verification.
HIPAA / BAA
Execute the published BAA in the console before sending PHI. The API uses HIPAA-eligible AWS services in the PHI path.
A BAA is a contract, not a certification.GDPR / DPA
GDPR Article 28 DPA, EU processing, SCCs and region-specific privacy addenda are published.
Omi Health B.V. is established in the Netherlands.SOC 2 Type II
Not currently certified. Auditor engagement is the next external-assurance milestone.
We will publish status only after the engagement begins.ISO/IEC 27001
Not currently certified. Formal certification is being evaluated after the SOC 2 workstream.
No ISO certification is claimed today.One visible processing boundary.
This scope describes the hosted Speech-to-Text Developer API. Open-model and customer-managed deployments run inside the environment you control.
Sends audio over TLS using an account-scoped API key.
Transcription and customer-content processing remain in eu-central-1.
Audio is deleted after processing; async results follow your selected expiry.
Identity is separate. Console authentication runs in Azure Sweden Central and processes account and authentication data—not audio, transcripts or PHI. Cloudflare serves the website and DNS; customer API content does not transit the website CDN.
Security in the product.
Concrete controls from the production technical and organisational measures.
Encryption
TLS for external traffic. Customer-content stores use AWS KMS customer-managed keys with rotation.
Credential handling
API keys are shown once and stored as SHA-256 hashes. Service secrets live in AWS Secrets Manager.
Least privilege
Role-based access, scoped IAM and no standing human access to customer content.
Immutable audit
Content-free security and compliance events are written to KMS-protected, Object-Locked storage.
Tenant isolation
Keys, jobs, results and vocabulary are account-scoped, with authorization on every retrieval.
Data minimisation
Customer content is excluded from operational logs and backups; deletion is enforced independently.
Read the source documents.
Public terms and data-protection documents are available without a sales call.
Need evidence for your review?
Request the enterprise security pack, report a security concern, or check current service health.