Back to OmnyID

Security & Incident Response

Effective date: July 5, 2026

1. Reporting a security issue

Send security reports to [email protected] with the subject line Security report. Include affected URLs, accounts, steps to reproduce, impact, and any proof-of-concept details needed for verification.

2. Intake and triage

  • Acknowledge receipt as soon as practical.
  • Validate the report, classify severity, and begin containment if the issue is real.
  • Restrict live changes to the minimum needed for containment and service protection.

3. Incident response baseline

  1. Identify the affected systems, data classes, and customer scope.
  2. Contain the issue, revoke or rotate credentials if required, and preserve relevant logs.
  3. Remediate the root cause and verify the fix.
  4. Notify affected users and counterparties when required by law or material impact.
  5. Document the incident, timeline, impact, and follow-up controls.

4. Breach-notification baseline

Where OmnyID determines that a security incident materially affects customer data, account integrity, or legal obligations, OmnyID will provide notice through the account email on file and, where appropriate, additional in-product or site messaging. The exact timing depends on verification, containment, legal obligations, and the accuracy of the impact assessment.

5. Security boundaries today

OmnyID is still an evolving system. Security posture depends on the active deployment model, enabled integrations, operator configuration, and whether features are self-hosted, hosted, or preview-only. Do not treat every feature path as having the same privacy or zero-access guarantees without checking the active deployment documentation.