Security
How we protect your data.
Security is a core responsibility at Omnidata. The following outlines the controls, practices, and standards we maintain to keep your data safe.
Encryption
All data stored on Omnidata infrastructure is encrypted at rest using AES-256. Data in transit between your browser and our servers, and between internal services, is protected using TLS 1.3. Encryption keys are managed through a dedicated key management service and rotated on a regular schedule.
Infrastructure
Omnidata is hosted on ISO 27001-certified cloud infrastructure with automatic scaling and redundancy across multiple availability zones. We conduct regular vulnerability scans and infrastructure audits. Dependency updates are applied on a rolling basis with automated security patching for critical CVEs.
Compliance
Omnidata operates in compliance with Undang-Undang Perlindungan Data Pribadi (UU PDP), Indonesia's personal data protection law. We conduct annual reviews of our data handling practices to remain aligned with applicable regulations. Customers with specific compliance requirements should contact us to discuss data processing agreements.
Access Controls
Internal access to customer data is restricted on a need-to-know basis using role-based access controls. All administrative access requires multi-factor authentication and is logged in tamper-evident audit trails. Employees undergo security training during onboarding and annually thereafter.
Application Security
Our development process includes code review gates, static analysis, and dependency scanning on every pull request. We maintain a responsible disclosure program and work with security researchers to address reported vulnerabilities promptly. Critical security patches are deployed within 24 hours of verification.
Data Retention and Deletion
Customer data is retained according to your subscription settings. When you close your account or request data deletion, your data is removed from production systems within 30 days and from backup systems within 90 days. Deletion requests can be submitted to [email protected].
Incident Response
We maintain a documented incident response plan with defined severity levels and escalation paths. In the event of a data breach affecting your information, we will notify you within 72 hours of becoming aware of the incident, in line with applicable regulatory requirements.
Contact
To report a security vulnerability, please email [email protected]. We ask that you give us reasonable time to investigate and address issues before any public disclosure. For general security questions, contact [email protected].