Why we built Omit
Three years of watching healthcare data leak through everyday copy-paste, not hackers, taught us that the only real fix is offline-first software. Here is why we built Omit that way.
For three years before Omit, we built a healthcare software company. We spent that time inside hospitals, billing offices, and clinics, watching how people actually work, not how a compliance binder says they are supposed to work. And what we saw, over and over, was not a hacker breaching a firewall or a laptop stolen from a car. It was a nurse copy pasting a patient's chart into a chatbot to draft a summary faster. It was a biller emailing a spreadsheet export because the internal portal was slow that afternoon. It was routine. Nobody meant harm, and nobody set off an alarm, because there was not one built to catch this. The tools guarding that data watch files moving across a network and endpoints connecting to the internet. None of them watch a keystroke, and that gap between "a file left the building" and "a person just pasted PII into a browser tab" is where the real exposure lives.
We did not have to imagine how common this is. The numbers backed up what we were seeing firsthand.
Average cost of a US healthcare data breach.
of employees paste company data into GenAI prompts.
Copy-paste is the top corporate data-exfiltration vector.
An IBM-based analysis published by HIPAA Journal puts the average cost of a US healthcare data breach at $7.42 million, the costliest industry for 14 years running. HHS OCR figures, also via HIPAA Journal, show 772 healthcare breaches reported in 2025 alone, affecting roughly 138.5 million people. Those are the breaches that get investigated and disclosed. The everyday leak we watched, the copy-paste into a chatbot, mostly never becomes a headline, because there is no breach notification for a paste nobody logged.
The LayerX Enterprise AI and SaaS Data Security Report puts a number on the behavior we saw daily: 77 percent of employees paste company data into GenAI prompts like ChatGPT and Copilot, and 40 percent of files uploaded to GenAI tools contain PII or PCI data. The same research found that copy-paste has overtaken file transfer as the leading corporate data-exfiltration vector, as covered by SC Media. File-centric data-loss-prevention tools were built to watch files leave, so a clipboard paste is structurally invisible to them. And it is not only text. Fierce Healthcare and HIPAA Journal reporting suggests roughly 1 in 4 of ChatGPT's 800 million-plus weekly users submits a healthcare-related prompt in a given week, into a consumer product that is not built or contracted to be HIPAA-compliant. Netskope's 2026 threat research puts the average organization at 223 GenAI data-policy violations a month. None of that requires an attacker. It only requires a deadline and a copy shortcut.
The only fix that actually holds is structural: make the sensitive data never leave the device in the first place.
Here is the conclusion we kept coming back to: you cannot train, warn, or govern your way out of this at scale. Every policy, every DLP rule, every "please do not paste PII" reminder is a request that a person, on a deadline, with good intentions, has to remember to honor every single time. That is not a control. It is a hope. The only fix that actually holds is structural: make the sensitive data never leave the device in the first place. If nothing goes out, there is nothing for a chatbot, an inbox, or a cloud API to leak, no matter what anyone pastes or forgets to redact.
That is why Omit runs entirely offline. Not offline as a checkbox for a compliance form, offline as the whole architecture. Detection, redaction, transcription, and summarization all happen on the machine in front of you. There is no account to create, no telemetry being collected, and no server on the other end of a network call, because there is no network call. It is not a promise you have to take on faith. Pull the network cable and Omit keeps working exactly the same, because it was never depending on the network to begin with.
Omit is one suite built around that single idea, expressed across five apps. Redact finds and redacts PII in text, email, CSV, Excel, PDF, and scanned images. Voice handles private voice typing and offline transcription with transcript redaction built in. Convert does local file conversion and metadata scrubbing. Meet does bot-free meeting recording, local transcription, diarization, and offline summaries. And Clipboard Guard, running alongside all of them, sits between copy and paste in any app or browser, redacting on the way in so a chatbot never sees the raw text at all, with a deliberate, logged override for the moments you genuinely need to paste the real thing. Every app shares one offline engine and one design, so it behaves the same way whether you are redacting a PDF or guarding a clipboard paste.
We also wanted to know, honestly, whether a fully offline engine could actually detect PII as well as a cloud service built for exactly this. So we built our own benchmark and ran it against Google Cloud DLP twice, once using Google's default configuration and once giving Google the exact entity types to look for, across a synthetic two-language corpus covering everything from national IDs to bank routing numbers. Omit matched or outperformed Google DLP's default configuration on all 34 entity types we tested, and matched or outperformed Google's best configuration in either mode on 30 of those 34, 22 outright wins and 8 ties. On 17 entity types, Omit left zero PII text visible in the output while Google's default configuration left the entire raw string exposed. We are publishing the methodology honestly: this is our own harness, our own corpus, run on 2026-07-22 against Google Cloud DLP v2, and we would rather show our work than round up.
We are not done. There are entity types we are actively improving, and we will keep saying so plainly as that work lands, the same way we are being plain about the benchmark above. What we will not do is compromise on the offline part. That is the whole point.
Omit is releasing soon. If you want to know the moment it ships, reach us at sales@omitsys.com and we will let you know.