Security

Security

OMAI · OMAI Software Ltd. · Company No. 517341764 · Last updated: July 2026


The security of businesses’ and their customers’ data is a top priority. Below are the key security controls we apply.

Encryption & secure transport

  • All web traffic is encrypted in transit over HTTPS (TLS 1.2 or 1.3), with HSTS enabled.
  • Data is encrypted in transit, and at rest using Azure platform-managed encryption for our database and file storage.

Secret management

  • Each customer’s WhatsApp access token is stored in Azure Key Vault, reached through a managed identity.
  • Our database holds a reference to the vault entry, not the WhatsApp token itself. Payment card tokens are stored encrypted (AES-256-GCM).

Webhook verification

  • Inbound webhooks from Meta are authenticated with an HMAC-SHA256 signature check, so unsigned or forged payloads are rejected.
  • The service refuses to start message processing without live provider credentials, rather than falling back to an unauthenticated mode.

Access controls

  • Role-based access control for your team (Owner / Admin / Agent / Viewer). You choose each teammate’s role when you invite them, and the default is a limited, non-administrative role.
  • Every request is scoped to a single organization, and membership is re-checked against the database on each request — so one organization’s users cannot reach another’s data.
  • Inside the product, each role is granted only the permissions it needs. A separate, restricted OMAI operator role exists for support; the changes it makes to an organization’s account are recorded in an audit log.

Audit logging

  • Sensitive actions (permission changes, billing changes, data export and deletion requests) are recorded in an audit log you can review in the dashboard.

Data minimization

  • Message content is used solely to operate the service and produce replies. It is processed by Microsoft Azure OpenAI as our sub-processor; we send it to no one else.
  • We do not sell personal data, and we do not use message content for advertising. Our AI sub-processor does not use customer content to train its models.

Hosting

  • The service is hosted on Microsoft Azure in the EU (Sweden Central) — application, database, storage and secrets.
  • Some processing by our subprocessors — for example AI inference, message delivery, sign-in and payment processing — may occur in other regions, including outside the EU. See the Privacy Policy for how international transfers are handled.

Secure development & testing

  • Security-relevant behaviour — webhook authenticity, tenant isolation and sign-in — is covered by automated tests that run on every change before release.
  • Our code is scanned for accidentally committed secrets on every change, and the production build output is checked for credential leaks before it ships.

Your part

  • Security is shared. Keep your password private and unique, and never reuse it elsewhere.
  • Invite only the people who need access, and give each teammate the least access that lets them do their job.
  • Tell us straight away if you think an account has been accessed without permission.

Responsible disclosure

Found a security issue? We’d like to hear about it and will handle it responsibly. Write to us: support@omai-software.com