Security Addendum
Omega's baseline security-control framework and the process for contractual customer assurance.
Published following operator-authorized Omega privacy, security, claims, and operational review. External counsel review is not recorded.
Security Addendum is public procurement information, not an executed agreement. Qualified external counsel must review the customer-specific agreement before signature or reliance.
Application
This page describes Omega's baseline control framework. Contractual commitments apply only when incorporated into an executed agreement or security addendum. No certification, audit opinion, or regulatory attestation should be inferred unless Omega identifies it expressly.
Security governance
Omega assigns security ownership, uses risk-based policies and review gates, and records evidence for material product, infrastructure, access, connector, and release changes.
Identity and access
Omega uses authenticated access, scoped roles, service identities, credential and secret custody, and review of privileged operations appropriate to the environment. Customers are responsible for their administrators, users, endpoints, and enabled connectors.
Encryption and secrets
Omega uses encrypted transport for supported service connections and managed encryption for applicable storage. Secrets and signing material are kept outside public source code and are provided to runtimes through controlled custody mechanisms.
Development and change control
Material code changes follow defined scope, review, testing, evidence, release-captain promotion, and deployment boundaries. Security-sensitive changes receive additional review. Dependencies and vulnerabilities are assessed and remediated based on risk.
Logging and monitoring
Omega records operational, security, workflow, and release events appropriate to the service. Access to logs is limited and retention follows security, evidence, privacy, and legal requirements. Monitoring coverage varies by component and maturity.
Incident response
Omega maintains procedures to identify, contain, investigate, remediate, and learn from security incidents. Customer notice is provided as required by the applicable agreement and law after Omega confirms a reportable event.
Resilience
Managed backups, recovery procedures, queue controls, deployment rollback, and provider redundancy are used where appropriate. Recovery objectives and uptime commitments exist only when stated in an executed SLA or order.
Subprocessors and suppliers
Omega assesses providers according to the data, service, and risk involved and contractually requires appropriate protection where they process Customer Personal Data. The Subprocessors page identifies core and conditional processing providers.
Assurance requests
Customers may request security documentation, questionnaires, or contractual commitments through security@omeganeural.com. Disclosure may require confidentiality, scope limits, current evidence, and reasonable scheduling.
Read this page with the related policy, trust, and service information that applies to your use of Omega.