Back to home

Security & Compliance

Last updated: June 19, 2026

Trust is at the heart of an immigration consultant's work. Openomi is built security- and compliance-first: your data and your clients' data are hosted in Canada, encrypted, and never used to train AI models. Here is, in plain terms, how we protect your information.

Contents

Overview

Openomi runs on Amazon Web Services (AWS) infrastructure in the Canadian ca-central-1 region. Security is built in by design: end-to-end encryption, strict per-account isolation, access logging, and data minimization.

Canadian data residency

All of your data — accounts, cases, uploaded documents, audit results — is stored and processed in data centres located in Canada (AWS ca-central-1 region).

  • Storage: PostgreSQL database and files (S3) hosted in Canada.
  • No off-shore storage: your documents are not transferred abroad for storage.
100% Canadian hosting — a decisive advantage for organizations and clients who care about data sovereignty.

Encryption

  • In transit: all communications are encrypted via TLS 1.3 (HTTPS).
  • At rest: data and documents are encrypted (AES-256) with keys managed by AWS KMS.

Authentication & access control

  • Accounts: authentication managed by Amazon Cognito (password + secure tokens).
  • Two-factor authentication (2FA): authenticator-app (TOTP) verification is available — enable it in Settings → Security.
  • Isolation: each consultant's and client's data is strictly isolated (access limited to the account owner).
  • Rate limiting: anti-abuse protections are applied to the API.

AI usage & model training

Openomi uses AI models (Google Gemini, AWS Bedrock) for case analysis, document generation, and language-test scoring.

  • No training on your data: our AI providers are bound by data processing agreements (DPAs) with a no-training clause — your data is never used to improve their models.
  • Inference only: data sent for analysis is not retained by providers beyond processing.
  • Transparency: AI-assisted recommendations are identified as such; human review is still recommended.
Your client files never feed AI model training. Period.

Regulatory compliance

  • PIPEDA: compliance with Canada's federal private-sector privacy law.
  • Quebec Law 25: a Privacy Impact Assessment (PIA) has been completed; access, rectification, deletion and portability rights are honoured.
  • Professional confidentiality: data is not disclosed to third parties; you keep control over importing/exporting your clients' data.

Sub-processors

We rely on a limited set of sub-processors, all bound by data processing agreements (DPAs) and standard contractual clauses:

  • AWS: hosting, database, storage, AI (Bedrock) — Canada region.
  • Google: Gemini AI models (DPA, no training).
  • Stripe: payments (PCI-DSS Level 1 certified).
  • Twilio: SMS/voice notifications (reminders, language tests).

Logging & incident response

  • Logs: access and API calls are logged and monitored.
  • Incident response: a documented plan is in place; in the event of a confirmed breach of personal information, notification is issued within 72 hours, in accordance with PIPEDA and Quebec Law 25.

A security question?

To report a vulnerability or ask about our security posture, write to us: security@openomi.io

© 2026 Openomi — Daemon Craft Inc.