Don't take our word for it. Verify it.
Omit is built to be checked by your IT and compliance team. Pull the plug and watch it keep working. Nothing depends on the network.
Verify the offline claim yourself
The strongest proof is a test you run, not a badge we show. Any reviewer can confirm the offline promise on their own hardware.
- 01
Isolate a machine
Put a Windows machine on an isolated network or disconnect it entirely.
- 02
Run a full redaction
Detect, redact, transcribe, and summarize as you normally would. Everything works unchanged.
- 03
Watch the network
Monitor traffic during the run. Omit makes no outbound requests, and there is no analytics endpoint to disable.
Local-only operation
All detection and redaction runs on-device, always.
No telemetry
We collect nothing. There is no analytics endpoint to disable.
Code-signed builds
Signed Windows installers you can validate before rollout.
Encryption and licensing
The Redaction Vault stores reversible tokens so authorized users can re-identify data later. It is sealed with modern cryptography and fails closed on the wrong key.
Encrypted vault
Reversible tokens are sealed with AES-256-GCM. Keys are derived with Argon2id and protected by Windows DPAPI.
Fail-closed by design
If a license, vault key, or engine is uncertain, Omit refuses rather than leaks. A wrong key returns opaque data, never plaintext.
Offline licensing
License keys are signed with Ed25519 and activated by pasting the key. There is no server contact.
Compliance posture
We are candid about what is certified versus what is true by design. Local-only operation makes most controls inherent, not aspirational.
Local-only operation makes most controls inherent, not aspirational. We are honest in this Trust Center about what is certified and what is by-design.