Skip to content
Omniphylax

How we handle access to your cloud.

Omniphylax needs to see your configuration to audit it. This page explains what we ask for, what we keep, and what we are still working on.

Read-only by design

You connect an account by creating a role from our template. On AWS that is an IAM role limited to read-only audit permissions. On Azure it is the built-in Reader and Security Reader roles on the subscriptions you choose.

These roles can read configuration but cannot change it. Fixes are written as code for your team to review and apply. You can read the template before you use it and revoke access at any time by deleting the role.

No long-lived secrets

We do not ask for access keys, passwords or client secrets. On AWS we assume your role through AWS STS, with an external ID unique to your organization, and receive credentials that expire within the hour. On Azure you grant consent to our application in your tenant, and each scan uses a short-lived token.

Isolated by tenant

Inventory, findings and reports belong to one organization. Every request is scoped to the organization making it, so one customer's data is never returned to another.

What we send to the AI model

The checks themselves are deterministic and run without AI. We use a language model to explain a finding, rank it and draft a fix.

For that, the model receives the finding and the configuration of the affected resource. It does not receive credentials, and account identifiers are replaced before the request is sent. Your data is not used to train models.

What we are working toward

  • SOC 2 readinessPlanned
  • An independent penetration test before general availabilityPlanned

We will update this page as each one is completed. Neither is in place today.

Report a security issue

Email [email protected]. We read every report and will reply to confirm we have received it.