Skip to content

Don't take our word for it. Verify it.

Omit is built to be checked by your IT and compliance team. Pull the plug and watch it keep working. Nothing depends on the network.

GDPR-readyby-designNo cloudzero transmissionAudit reportsper-runFail-closedEd25519 keysKeyboard-firstWCAG AA

Verify the offline claim yourself

The strongest proof is a test you run, not a badge we show. Any reviewer can confirm the offline promise on their own hardware.

  1. 01

    Isolate a machine

    Put a Windows machine on an isolated network or disconnect it entirely.

  2. 02

    Run a full redaction

    Detect, redact, transcribe, and summarize as you normally would. Everything works unchanged.

  3. 03

    Watch the network

    Monitor traffic during the run. Omit makes no outbound requests, and there is no analytics endpoint to disable.

Local-only operation

All detection and redaction runs on-device, always.

No telemetry

We collect nothing. There is no analytics endpoint to disable.

Unsigned while in beta

The first public build carries no code-signing certificate, so Windows SmartScreen warns on it. A certificate is on the list for the stable release. We would rather say so here than let a dialog say it for us.

Encryption and licensing

The Redaction Vault stores reversible tokens so authorized users can re-identify data later. It is sealed with modern cryptography and fails closed on the wrong key.

AES-256-GCM

Encrypted vault

Reversible tokens are sealed with AES-256-GCM. Keys are derived with Argon2id and protected by Windows DPAPI.

Refuses on doubt

Fail-closed by design

If a license, vault key, or engine is uncertain, Omit refuses rather than leaks. A wrong key returns opaque data, never plaintext.

Ed25519

Offline licensing

License keys are signed with Ed25519 and activated by pasting the key. There is no server contact.

What leaves your machine

Nothing. That is the whole answer, but a procurement team needs the itemised version, so here it is.

DataLeaves deviceDetail
Document contentsNeverDetection and redaction run in a local process. There is no upload path in the product.
Detection resultsNeverEntities and spans exist in memory and in the local audit report. They are not transmitted.
Audio and transcriptsNeverRecording, transcription and summarisation all run on the device, including the models.
Vault contentsNeverThe reversible token mapping is encrypted at rest on the local disk.
Licence activationNeverKeys are Ed25519 signatures verified offline. There is no activation server to call.
Telemetry and crash reportsNeverThere is no analytics endpoint. The product ships without one rather than with one switched off.
Update checksOnly if you askUpdates are installed from a file you obtain. The application does not poll for them.
Website cookiesNeverThis site sets no cookies and stores nothing in your browser. There is no consent banner because there is nothing to consent to.
Website form fieldsOnly what you typeThe contact and notify forms post what you enter to Web3Forms, a form relay that forwards it to our inbox. No product data passes through it.
Payment details (a purchase)To Lemon SqueezyLemon Squeezy is our payment processor and merchant of record for licence purchases. It collects your name, email address, and payment details to process the transaction; no payment detail is ever sent to or stored by Omit Systems.
Licence delivery emailTo our email providerAfter a purchase, the email address you used and the licence key issued are sent to our transactional email provider so it can deliver the licence email to you.
Order and licence recordsStored in Cloudflare D1The buyer's email address, paired with the licence key issued, is stored in a Cloudflare D1 database Omit Systems operates, so a lost key can be resent or an order looked up.
Every class of data Omit touches and whether any of it leaves the machine. Procurement reviewers can quote this row by row.Verified 23 July 2026.

Where we stand, rule by rule

Each entry says plainly whether something is certified, supported by design, or simply not held. A claim you can check is worth more than a badge you cannot.

GDPR

Supported by design, not certified

Also DSGVO in Germany and Austria, RGPD in France and Spain.

There is no GDPR certificate to hold; GDPR is a regulation you comply with, not a badge you are awarded. What we can say precisely is this. Because processing happens entirely on your machine, we are not a processor of your personal data, so there is no Article 28 processing agreement needed for the product. Because nothing is transmitted, the transfer rules in Article 44 and the chapter that follows are not engaged, which removes the hardest part of most vendor assessments. Redaction before disclosure is data minimisation applied at the point of sharing, which supports Article 5. The audit report gives you the record of what was removed.

EU AI Act

Relevant to how you deploy AI, not a certification

Omit is not itself a high risk AI system, but it is the control that makes safer use of one practical. The Act does not stop staff pasting personal data into a general purpose model, and neither does an acceptable use policy. Removing identifiers before the paste is a control that operates on the endpoint and is logged there. See the timeline page for every applicable date, including the move of high risk obligations to 2 December 2027.

NIS2

Reduces supply chain exposure

NIS2 asks essential and important entities to manage supply chain risk, and public administration and health are both in scope. A tool that never opens a network socket removes an entire category of that risk. There is no vendor endpoint to assess, no availability dependency on us, and no third party breach that can reach your documents, because your documents were never at a third party.

HIPAA

No BAA required, and available on enterprise terms

A Business Associate Agreement is required when a vendor receives protected health information. Omit never receives any: it runs on your machine, and no PHI reaches Omit Systems at any point. On the plain reading of the rule we are a software supplier rather than a business associate, in the same way a locally installed word processor is not one. We would rather state that clearly than let silence look like evasion. That said, if your compliance team requires a signed BAA to complete an assessment, we will review and sign one on enterprise terms. Ask us.

SOC 2 and ISO 27001

Not held. We will not imply otherwise

We hold neither today. Both certify the operation of an organisation that handles customer data, and both are worth having as we grow. We would rather tell you plainly than display a badge that means something narrower than it appears. What we offer instead is a claim you can verify in a minute without reading an auditor's report: disconnect the machine and use the product.

Subprocessors

None for product data: no customer document or detection result ever reaches us, so there is nothing to delegate there. Purchasing a licence is different. Three subprocessors handle purchase and licence-delivery data on our behalf: Lemon Squeezy (payment processing), our transactional email provider (licence delivery), and Cloudflare D1 (storage of order and licence records). The website and the purchase flow are hosted separately from the product and never receive document content. If you require a data processing agreement for the website or the purchase flow, we will sign one.

What procurement asks

How do we verify the offline claim ourselves?

Disconnect the machine from every network, then run a redaction, a transcription and a file conversion. All three complete normally. This is the recommended acceptance test because it does not depend on trusting us, our documentation, or an auditor. If you prefer, run it with a network monitor attached and observe that the process opens no sockets.

Do you have access to our documents at any point?

No. There is no upload path, no support tunnel and no remote assistance feature. If you send us a document while raising a support ticket, that is an email you chose to send, and we ask you not to. We cannot retrieve, view or recover your files, including if you lose them.

What happens if your company ceases trading?

The software keeps working. Licences are perpetual and verified offline against a signed key, so there is no activation server whose shutdown would disable your installation. This is a deliberate design choice and it is the main practical difference between a perpetual local licence and a subscription.

Where is our data stored?

Wherever you put it. Output files are written next to the originals or to a location you choose. The vault, if you use reversible tokens, is an encrypted file on the same machine. There is no Omit-controlled storage anywhere in the product.

Can administrators enforce policy across a fleet?

Yes. Administrators can restrict which operators are available and set a floor on which entity types must always be redacted. The effective policy is the intersection of the licence ceiling and the administrative restriction, so a local user cannot widen what an administrator has narrowed.

Is the detection perfect?

No, and any vendor claiming otherwise is selling you something. Detection is statistical and recall is never one hundred percent on arbitrary text. Two things follow. First, Omit fails closed: where a detection is uncertain the default is to redact rather than release. Second, review remains available on every run, because the responsible workflow for a high stakes disclosure includes a human reading the result.

Compliance posture

We are candid about what is certified versus what is true by design. Local-only operation makes most controls inherent, not aspirational.

Local-only operation makes most controls inherent, not aspirational. We are honest in this Trust Center about what is certified and what is by-design.