Each entry says plainly whether something is certified, supported by design, or simply not held. A claim you can check is worth more than a badge you cannot.
Supported by design, not certified
Also DSGVO in Germany and Austria, RGPD in France and Spain.
There is no GDPR certificate to hold; GDPR is a regulation you comply with, not a badge you are awarded. What we can say precisely is this. Because processing happens entirely on your machine, we are not a processor of your personal data, so there is no Article 28 processing agreement needed for the product. Because nothing is transmitted, the transfer rules in Article 44 and the chapter that follows are not engaged, which removes the hardest part of most vendor assessments. Redaction before disclosure is data minimisation applied at the point of sharing, which supports Article 5. The audit report gives you the record of what was removed.
Relevant to how you deploy AI, not a certification
Omit is not itself a high risk AI system, but it is the control that makes safer use of one practical. The Act does not stop staff pasting personal data into a general purpose model, and neither does an acceptable use policy. Removing identifiers before the paste is a control that operates on the endpoint and is logged there. See the timeline page for every applicable date, including the move of high risk obligations to 2 December 2027.
Reduces supply chain exposure
NIS2 asks essential and important entities to manage supply chain risk, and public administration and health are both in scope. A tool that never opens a network socket removes an entire category of that risk. There is no vendor endpoint to assess, no availability dependency on us, and no third party breach that can reach your documents, because your documents were never at a third party.
No BAA required, and available on enterprise terms
A Business Associate Agreement is required when a vendor receives protected health information. Omit never receives any: it runs on your machine, and no PHI reaches Omit Systems at any point. On the plain reading of the rule we are a software supplier rather than a business associate, in the same way a locally installed word processor is not one. We would rather state that clearly than let silence look like evasion. That said, if your compliance team requires a signed BAA to complete an assessment, we will review and sign one on enterprise terms. Ask us.
Not held. We will not imply otherwise
We hold neither today. Both certify the operation of an organisation that handles customer data, and both are worth having as we grow. We would rather tell you plainly than display a badge that means something narrower than it appears. What we offer instead is a claim you can verify in a minute without reading an auditor's report: disconnect the machine and use the product.
None for product data: no customer document or detection result ever reaches us, so there is nothing to delegate there. Purchasing a licence is different. Three subprocessors handle purchase and licence-delivery data on our behalf: Lemon Squeezy (payment processing), our transactional email provider (licence delivery), and Cloudflare D1 (storage of order and licence records). The website and the purchase flow are hosted separately from the product and never receive document content. If you require a data processing agreement for the website or the purchase flow, we will sign one.