Security
Security governance, access, secrets, development, monitoring, incident response, resilience, and assurance boundaries.
Published following operator-authorized Omega privacy, security, claims, and operational review. External counsel review is not recorded.
Security is published as current informational posture, not legal advice, certification, or a contractual commitment. External counsel approval is not recorded.
Security governance
Omega assigns security ownership, uses risk-based control standards, and requires evidence and review for sensitive changes. Security posture evolves with the product and service configuration.
Access control
Authentication, scoped roles, service identities, least-privilege access, and controlled administrative paths protect environments. Customers control their users, administrators, connectors, and endpoint security.
Data and secret protection
Supported connections use encrypted transport. Managed infrastructure provides storage protection appropriate to the service. Secrets, signing material, and provider credentials are kept outside public source code and supplied through controlled runtime custody.
Secure delivery
Product changes follow defined scope, isolated implementation, tests, review, release-captain promotion, and deployment evidence. Security-sensitive, billing, identity, data, and lawful-runtime changes receive additional scrutiny.
Monitoring and evidence
Omega records operational and security events appropriate to the component, including access, workflow, release, queue, and provider signals. Logs are protected and retained according to risk, privacy, contract, and legal requirements.
Incident response
Omega investigates suspected compromise, contains affected systems, preserves evidence, remediates causes, and notifies affected customers as required by agreement and law.
Resilience
Backups, queue controls, rollback, recovery procedures, and provider-aware routing are used where appropriate. Specific recovery and uptime targets require a signed SLA.
Assurance boundary
Omega does not claim SOC 2, ISO 27001, penetration-test results, independent certification, or guaranteed security unless current evidence is expressly published or provided under agreement.
Report a concern
Send suspected vulnerabilities or incidents to security@omeganeural.com with the affected URL or service, observed behavior, and safe reproduction details. Do not access or retain data beyond what is necessary to report the issue.
Read this page with the related policy, trust, and service information that applies to your use of Omega.