Loading...
Loading...
Real-time compliance posture • Auditable evidence • Cryptographic proof
Every control is backed by code, not just policy. Explore our live compliance posture across SOC 2, NIST AI RMF, ISO 42001, and the EU AI Act.
This is a self-assessment, not an independent audit. OmegaEngine evaluates its own controls against these frameworks and is not SOC 2 / ISO 42001 certified. See the full self-assessed report for scope and caveats.
All hosted infrastructure runs in the United States today. Hosted EU residency is on the roadmap and discussed per contract — it is not yet available. Strict residency or air-gap requirements are met today by self-hosting the engine on your own infrastructure.
Full list including payments, analytics, and error monitoring: subprocessors.
GDPR, CCPA, and international data protection
Service agreement and usage terms
Defense-in-depth technical controls
Severity levels, escalation, and recovery
Per-tier retention windows and compliance
GDPR Art. 28 DPA for enterprise customers
Who processes your data, why, and where it lives
View the full compliance assessment with per-control evidence, framework scores, and attestation. Print-ready for auditors.
Full self-assessment packages with evidence chains and continuous red-team results (5,023-vector library) available under NDA.
The compliance posture above is self-assessed. This part is not: every Agent Security Attestation we issue is signed with an Ed25519 key and committed to a signed, tamper-evident transparency log (RFC 6962). Anyone can verify one offline — trusting only the public key and the math, never our servers.
# no id? run the live sample — verifies against the published key, offline npx -y @omegaengine/verify@latest sample --api=https://omegaengine.ai # ✓ VERIFIED # or verify an attestation you hold (replace <id>) curl -s https://omegaengine.ai/api/verify/<id> > attestation.json npx -y @omegaengine/verify@latest attestation.json # ✓ VERIFIED
Found a vulnerability? We reward responsible disclosure of qualifying issues; reward amounts are determined case-by-case based on severity.
Report a VulnerabilityStatic self-assessment (live probe unreachable) • SOC 2 Type II observation period planned • Contact security@omegaengine.ai for audit requests