Your data stays on your Mac.
OMEGA was built on a privacy-first architecture: local-first execution, your own API keys, signed safety policies, and an air-gap roadmap for Enterprise. The same patterns that make OMEGA fast and cheap also make it the easiest AI agent on the market to defend in a security review.
How we keep your data yours.
Local-first execution
OMEGA runs on your Mac. Your conversations, your memory, your Automations, and your data live on your hardware. Nothing routes through OMEGA's servers in normal operation. The only outbound traffic is the runtime you configured: your own API keys, a supported Codex or Claude subscription connection, or local-only MLX.
BYOK and subscription handling
API keys for OpenAI, Anthropic, Google, and other providers stay encrypted on your device. Codex and Claude subscription connections are handled as local runtime credentials. OMEGA never stores, proxies, or sees your raw tokens. We can't bill you per-token because we never see the requests.
Encryption at rest and in transit
Local credentials and application secrets are protected with macOS Keychain-derived keys. Workspace and runtime boundaries authenticate every internal service call; selected external providers receive only the data required for the user-authorized request.
Signed-and-pinned safety policies
OMEGA's safety policies are signed and hash-pinned. They can't be silently changed: not by us, not by an attacker, not by the model. Tampering shuts the system down before it runs.
Enterprise air-gap deployment
Zero-network operation, outbound allowlist enforcement, and local-model-only execution are on the Enterprise roadmap, scoped case-by-case on custom terms. Standard plans remain local-first; full air-gap controls will be Enterprise-only.
Audit logging
Every agent action (tool calls, model invocations, file accesses, costs) is recorded in an append-only Action Journal. The journal is yours, on your Mac, and surfaces in the in-app dashboard.
Encryption details, surface by surface.
What’s encrypted, how it’s encrypted, and where the keys live. No hand-waving.
| Surface | Method | Notes |
|---|---|---|
| API keys and subscription connections | macOS Keychain (AES-256, hardware-backed where available) | Keys and subscription connection metadata live in your login keychain; OMEGA reads them only at the moment of an outbound provider call. |
| Local conversation + memory data | Bundled Postgres on a Unix socket; file-system-level FileVault encryption | Postgres database in ~/Library/Application Support/OMEGA/, accessible only by your macOS user. |
| Internal pub/sub (Gateway → Agent) | Bundled Redis 6380 with HKDF-derived password from per-install jwt_secret | Even another process on your Mac can't read the bus without the secret. |
| License + account data on the licensing server | TLS 1.3 in transit, AES-256 at rest, signed JWTs | central.myomega.ai stores only email + license info: no conversation content, ever. |
| App binary + updates | Apple Developer ID code signing, Apple Notarization, Tauri signed updater | Hardened runtime + library validation. Updates are signature-verified before install. |
What we’re defending against.
The threats we’ve thought through, and the controls that mitigate them. This is a living document; if you find a gap, please tell us.
Compromised AI provider keys
Mitigation: Keys live in your Keychain only; OMEGA can't leak what it doesn't see. Revocation is instantaneous via the provider's dashboard.
Malicious third-party MCP server
Mitigation: User-installed MCP servers are sandboxed and require explicit per-app approval gates before agents can call them. Always-allow lists are revocable from Settings.
Prompt injection / jailbreak attempts
Mitigation: Sensitive-action denial layer + Soul governance with hash-pinned policy. Risky tool calls trigger human-in-the-loop approval queue, not silent execution.
Runaway agent token costs
Mitigation: Neural-Fractal Agentic AI™ (NFA) budget authority enforces token + dollar caps at every cognitive scale. Per-task / per-day / per-week / per-month budgets in Settings.
Stolen device with active OMEGA install
Mitigation: FileVault encryption (recommended); license-server can deactivate stolen devices on request; Keychain protected by user password + device PIN.
Compromised licensing server
Mitigation: Server stores license metadata only: no conversation content. License JWTs are signed; offline grace period allows continued use even if the licensing server is unavailable.
Supply-chain attack on a dependency
Mitigation: SBOM generated per release; dependencies pinned by hash; reproducible builds; release artifacts signed by Apple Developer ID.
Where we stand.
We're honest about what's in place today versus what's in flight. Anything dated below is committed to in writing for Enterprise customers.
Independent reviews.
Reports are available under NDA via the legal contact form. Public summaries land here as audits complete.
- Scope
- Native macOS app + licensing server
- Auditor
- TBD (NCC Group / Trail of Bits / Cure53 shortlist)
- Deliverable
- Executive summary public; full report under NDA
- Scope
- Each release before signing
- Auditor
- Internal security review
- Deliverable
- Findings closed before release; high-severity items disclosed publicly
Found a vulnerability?
We welcome reports from security researchers. Our policy is below; operating within it protects you legally and earns you public credit (if you want it).
How to report
- 1. Submit through the security contact form
- 2. Include: affected component, reproduction steps, impact, and any proof of concept
- 3. We acknowledge within 24 hours and triage within 2 business days
Our commitments
- We acknowledge security reports within 24 hours.
- We triage and assign severity within 2 business days.
- We commit to a fix timeline based on severity (Critical: 7 days; High: 30 days; Medium/Low: next release cycle).
- We coordinate public disclosure with the researcher once a fix is available.
- We provide public credit (with permission) on this page's Acknowledgments section.
- We do not pursue legal action against good-faith security researchers operating within our policy.
What’s in scope
In scope: OMEGA native macOS app, central.myomega.ai, and the myomega.ai marketing site.
Out of scope: third-party AI providers (report to them directly), social engineering, physical attacks, denial of service, automated scanners against production, and pre-release features explicitly marked unstable.
Bug bounty: not currently offered; we credit researchers publicly and provide swag for substantive findings. A formal bounty program is on the 2027 roadmap.
Hall of fame.
Researchers who responsibly disclosed security issues, with their permission to be credited publicly.
None yet. Be the first. Report a vulnerability →
Every vendor that touches your data.
Full transparency on every third party we use that ever sees account or billing data. We’ll notify you 30 days before adding any new sub-processor that touches customer data.
Stripe, Inc.
Payment processing, billing, subscription management
- Data accessed
- Email, billing address, payment method
- Location
- United States (multi-region)
- Certifications
- PCI DSS Level 1, SOC 1, SOC 2
Resend, Inc.
Transactional email delivery (account activation, receipts, support)
- Data accessed
- Email address, name
- Location
- United States
- Certifications
- SOC 2 Type II
Twilio Inc.
Phone verification at signup, where required (Verify one-time SMS codes + Lookup line-type checks)
- Data accessed
- Phone number, verification metadata
- Location
- United States
- Certifications
- SOC 2 Type II, ISO 27001
Vercel, Inc.
Marketing website hosting + edge CDN
- Data accessed
- Public website traffic logs (anonymized IPs)
- Location
- Global edge network
- Certifications
- SOC 2 Type II, ISO 27001
Cloudflare, Inc.
DNS, DDoS protection
- Data accessed
- Public website traffic (no payload inspection)
- Location
- Global edge network
- Certifications
- SOC 2 Type II, ISO 27001, PCI DSS
Hostinger International Ltd.
Licensing server VPS hosting
- Data accessed
- Encrypted database snapshots, server logs
- Location
- United States, Lithuania
- Certifications
- ISO 27001
Every agreement, policy, and disclosure.
One place for procurement teams, lawyers, and security reviewers to find what they need.
Privacy Policy →
What data we collect (very little) and how we handle it
Terms of Service →
General terms governing your use of OMEGA
Lifetime License Agreement →
Perpetual EULA for lifetime tier buyers
Subscription License Agreement →
Auto-renewing EULA for monthly subscribers
Acceptable Use Policy →
What you may and may not do with OMEGA
Refund Policy →
Evaluate Pro via the $7 7-day trial; no refunds, all charges final
DMCA & Copyright Policy →
Copyright complaints, counter-notices, repeat-infringer policy, and AI-output responsibility
Third-Party and Model Notices →
Bundled runtimes, MLX/audio/image models, provider marks, package notices, and attribution scope
Data Processing Addendum →
DPA scope and request path for Pro and Team customers
Incident Response and Recovery →
Incident severity, response runbook, backup/restore policy, and notifications
Consumer Rights →
Jurisdiction-specific consumer, privacy, cancellation, and support rights
Accessibility Statement →
Accessibility posture, known limits, and feedback process
Legal Changelog →
Version history and legal review checklist before pricing or plan changes
Support Escalation Templates →
Templates for billing, copyright, account, vulnerability, and law-enforcement requests
Need more for procurement?
Sub-processor list and DPA template are above. For penetration test reports, security questionnaires, or custom procurement requirements, contact us.