OmniLink

Security

Security is foundational to OmniLink. We use a defence-in-depth model that combines hardened infrastructure, tenant isolation, strong identity, continuous monitoring, and a disciplined incident-response program. This page is the public summary of our security program. For implementation guidance on building secure agents on top of OmniLink, see the Security chapter in the documentation.

The shape of the program

OmniLink is built on a small number of well-understood building blocks: a Node.js API hosted on Google Cloud Run, a managed Supabase database for storage and authentication, a Python local runtime that executes tools on customer hardware, and integrations with third-party AI providers for inference. Each building block has a defined trust boundary, a documented threat model, and explicit controls. The program is reviewed at least annually, kept current with industry frameworks such as ISO/IEC 27001, SOC 2, NIST CSF, and the OWASP ASVS, and tuned by the lessons we learn from operating the platform.