Security
Encryption in transit and at rest, least-privilege access, and verified backups. Below is the actual posture, not the brochure.
Encryption
- In transit: TLS 1.2+ for all connections. HSTS enforced.
- At rest: AES-256 for all persisted data, including memories and backups.
- Secrets: HMAC-validated tokens; passwords are hashed with a modern adaptive KDF. We never store passwords in plaintext.
Access controls
- Strict least-privilege — engineers access production only via short-lived, audited credentials.
- No standing admin access to customer memory content. Access is purpose-bound and logged.
- Authentication supports passkeys and OAuth; we encourage phishing-resistant factors.
Backups
Encrypted backups run on a regular schedule and are restore-tested. Backups inherit the same encryption posture as primary storage.
Monitoring & detection
We aggregate security-relevant events and alert on anomalies. See Incident response for what happens when something goes wrong.
Responsible disclosure
Found a vulnerability? Email security@omegavault.app. We acknowledge within 48 hours and work with you on disclosure timing.
Honest gaps
We are not yet SOC 2 Type II or ISO 27001 certified. We have designed the architecture with those controls in mind and are on a path toward formal certification.