Security
Security
OMAI · OMAI Software Ltd. · Company No. 517341764 · Last updated: July 2026
The security of businesses’ and their customers’ data is a top priority. Below are the key security controls we apply.
Encryption & secure transport
- All web traffic is encrypted in transit over HTTPS (TLS 1.2 or 1.3), with HSTS enabled.
- Data is encrypted in transit, and at rest using Azure platform-managed encryption for our database and file storage.
Secret management
- Each customer’s WhatsApp access token is stored in Azure Key Vault, reached through a managed identity.
- Our database holds a reference to the vault entry, not the WhatsApp token itself. Payment card tokens are stored encrypted (AES-256-GCM).
Webhook verification
- Inbound webhooks from Meta are authenticated with an HMAC-SHA256 signature check, so unsigned or forged payloads are rejected.
- The service refuses to start message processing without live provider credentials, rather than falling back to an unauthenticated mode.
Access controls
- Role-based access control for your team (Owner / Admin / Agent / Viewer). You choose each teammate’s role when you invite them, and the default is a limited, non-administrative role.
- Every request is scoped to a single organization, and membership is re-checked against the database on each request — so one organization’s users cannot reach another’s data.
- Inside the product, each role is granted only the permissions it needs. A separate, restricted OMAI operator role exists for support; the changes it makes to an organization’s account are recorded in an audit log.
Audit logging
- Sensitive actions (permission changes, billing changes, data export and deletion requests) are recorded in an audit log you can review in the dashboard.
Data minimization
- Message content is used solely to operate the service and produce replies. It is processed by Microsoft Azure OpenAI as our sub-processor; we send it to no one else.
- We do not sell personal data, and we do not use message content for advertising. Our AI sub-processor does not use customer content to train its models.
Hosting
- The service is hosted on Microsoft Azure in the EU (Sweden Central) — application, database, storage and secrets.
- Some processing by our subprocessors — for example AI inference, message delivery, sign-in and payment processing — may occur in other regions, including outside the EU. See the Privacy Policy for how international transfers are handled.
Secure development & testing
- Security-relevant behaviour — webhook authenticity, tenant isolation and sign-in — is covered by automated tests that run on every change before release.
- Our code is scanned for accidentally committed secrets on every change, and the production build output is checked for credential leaks before it ships.
Your part
- Security is shared. Keep your password private and unique, and never reuse it elsewhere.
- Invite only the people who need access, and give each teammate the least access that lets them do their job.
- Tell us straight away if you think an account has been accessed without permission.
Responsible disclosure
Found a security issue? We’d like to hear about it and will handle it responsibly. Write to us: support@omai-software.com
