Security, privacy and compliance.
Where clinical data is processed, how it is protected, and which agreements and external assurances are available today.
Last reviewed 11 August 2026What is available today.
Certification status is shown as complete only after independent verification.
HIPAA / BAA
Execute the published BAA in the console before sending PHI. The API uses HIPAA-eligible AWS services in the PHI path.
A BAA is a contract, not a certification.GDPR / DPA
GDPR Article 28 DPA, EU processing, SCCs and region-specific privacy addenda are published.
Omi Health B.V. is established in the Netherlands.SOC 2 Type II
Not currently certified. Auditor engagement is the next external-assurance milestone.
We will publish status only after the engagement begins.ISO/IEC 27001
Not currently certified. Formal certification is being evaluated after the SOC 2 workstream.
No ISO certification is claimed today.One visible processing boundary.
This scope describes the hosted Speech-to-Text Developer API. Open-model and customer-managed deployments run inside the environment you control.
Sends audio over TLS using an account-scoped API key.
Transcription and customer-content processing remain in eu-central-1.
Audio is deleted after processing; async results follow your selected expiry.
Identity is separate. Console authentication is an Omi-operated Keycloak service in the same AWS Frankfurt region and processes account and authentication data—not audio, transcripts or PHI. Cloudflare serves the website and DNS; customer API content does not transit the website CDN. Speaker diarization distinguishes anonymous speakers within one recording; it does not identify people across recordings or create persistent voice profiles.
Security in the product.
Concrete controls from the production technical and organisational measures.
Encryption
TLS for external traffic. Customer-content stores use AWS KMS customer-managed keys with rotation.
Credential handling
API keys are shown once and stored as SHA-256 hashes. Service secrets live in AWS Secrets Manager.
Least privilege
Role-based access, scoped IAM and no standing human access to customer content.
Immutable audit
Content-free security and compliance events are written to KMS-protected, Object-Locked storage.
Tenant isolation
Keys, jobs, results and vocabulary are account-scoped, with authorization on every retrieval.
Data minimisation
Customer content is excluded from operational logs and backups; deletion is enforced independently.
Read the source documents.
Public terms and data-protection documents are available without a sales call.
Need evidence for your review?
Request the enterprise security pack, report a security concern, or check current service health.