Skip to content
OmniAxis
Get started
Security & trust

Your data stays yours. Every claim carries its source.

Your private competitive intelligence, and the profile you curate of your own company, stay isolated to your tenant, and every surfaced fact traces back to its source. This page also sets out the evidence discipline behind every claim we make about OmniAxis itself.

Tenant isolation Grounded in your profile Evidence provenance GDPR & DPA posture
Trust posture

Trust is a product property, not an appendix

Four commitments organise this page: your data is isolated to your tenant, agents are grounded in your curated profile, every surfaced claim carries provenance, and the GDPR and DPA posture is set out below.

Security, risk, and legal reviewers gate every deal, so this page is written for them. Every commitment here is backed by a shipped mechanism, named in the sections that follow.

The same discipline governs how we describe OmniAxis itself: every claim about the product is one we can back with evidence, and evidence, not badges, carries the argument.

Everything on this page describes generally available controls. Nothing here depends on a roadmap item.

Data isolation

A shared research library, a strictly private overlay

OmniAxis separates what every tenant shares from what only you can see. The model is simple enough to evaluate without an architecture review.

The shared intelligence library

Vendor profiles, evidence, and assessments derived from independent research form a common library that every tenant inherits. Nothing in it comes from any tenant's private data.

  • Built from independent, third-party research
  • Identical for every tenant
  • Never seeded with tenant uploads or private edits

Your private overlay

Which vendors you track, the documents you upload, your private annotations, and your own canonical company profile live in a tenant-private space. Other tenants cannot see any of it, and none of it is merged into the shared library.

  • Uploaded documents stay tenant-private
  • Your canonical profile is yours alone
  • Private edits never appear in shared profiles

Shared research in, private context on top. The two never mix.

Governance controls

Six controls a risk reviewer can evaluate

Role-based access, canonical grounding, tenant-private uploads, and governed exports can all be shown in a live working session. The isolation model and the DPA are documented for your legal review.

Tenant isolation

Each tenant's data is isolated. Your tracked vendors, private edits, and evaluation work are invisible to every other tenant, full stop.

Role-based access

Per-tenant, role-based access keeps users to what their role permits. Evaluation workspaces carry lead, committee, approver, and observer roles, so least privilege holds inside your own team as well.

Canonical grounding

You curate an authoritative profile of your own company. Agents read it as ground truth and never overwrite it. When independent evidence disagrees, the discrepancy is flagged for a human to review.

Tenant-private intelligence

Documents you upload are extracted and checked for contradictions against independent evidence inside your tenant only. They are never shared cross-tenant and never enter the shared library.

Governed exports

Exports of your own data are IP-marked and leak-guarded, with per-section permission gating. You can hand a report to a client or a board without wondering what else rode along.

GDPR & DPA posture

Processing is GDPR-aligned. A Data Processing Agreement is available on request, and sub-processor detail lives in the DPA, where legal teams expect to find it.

Source transparency

Where the evidence comes from

The shared library is graded from independent third-party evidence, and documentation you upload adds tenant-private evidence beside it.

We do not publish the source catalogue. A named list is a list a vendor can work backwards from, and evidence that can be targeted stops being independent. What you can inspect is the specific source behind any individual claim, in your own account, at the point the claim is made.

Financial-viability signals derive from documented records only. No private financial data enters an assessment, which means every financial signal we surface is one you could defend to a board or a regulator.

The more independent the evidence behind a claim, the higher the grade it can reach.

Evidence discipline

How we keep every claim honest

Grades are anchored to independent third-party evidence and to the documentation you upload, so every assessment traces to a record you can inspect.

Every ROI or outcome figure we publish carries its evidence class, illustrative or modelled, so you always know whether you are reading a value hypothesis or a measured result.

The DPA includes a plain-English summary of what data is processed and why, and we state only the certifications we genuinely hold.

Claims are graded, labelled, and sourced. That discipline is the product, not a disclaimer.

Security and trust questions

The questions that come up most often in risk and legal reviews.

How is my data isolated from other tenants?

Every tenant operates in a private space. Your tracked vendors, uploads, annotations, and evaluation work are invisible to other tenants, and the shared research library never contains tenant-private data.

What happens to documents I upload?

They stay tenant-private and never enter the shared library. Within your tenant, each upload is extracted and compared against the documented record; where your document contradicts a graded claim, the conflict is surfaced for your team to act on.

Can the AI invent or overwrite facts about my company?

No. Your curated profile is the ground truth agents read, and no agent can write to it. If independent evidence disagrees with something you have curated, you see the discrepancy and decide what to do with it; the profile stays exactly as you left it.

Where does the evidence come from?

From the independent documented record rather than from vendor marketing. We keep the source catalogue private by design, because a published list is one a vendor can work backwards from. The source behind any single claim is visible to you at the point that claim is made, and documentation you upload adds a tenant-private evidence lane beside it.

Do you lab-test products?

No. Grading in the shared library covers what the independent record already contains. When that record is silent on a claim, the assessment shows the gap; nothing is filled in with a guess.

Is any of the financial data private?

No. Financial-viability signals derive from documented records only.

Are you SOC 2 certified?

No. OmniAxis does not claim a certified SOC 2; certification is an open decision. The trust overview we share on request records the current status.

Do you offer a DPA, and are you GDPR-aligned?

Yes. Processing is GDPR-aligned, and a Data Processing Agreement, including sub-processor detail, is available on request.

How do you handle vendors' certification claims?

Each certification a vendor claims is graded by the evidence behind it. Where the evidence falls short, the gap becomes a validation question you can put to the vendor directly.

Match the next step to where your review stands

Evaluators still building the file can request the DPA and trust overview; teams cleared to proceed can talk to us today.

Request a tailored demo Request the DPA and trust overview