for security and procurement

Procurement, made painless.

Everything your security and vendor-management team asks for, gathered behind one link, so the path from yes to a signed contract stays short.

ISO 27001Certified ISO 9001Certified SOC 2 Type IIIn progress GDPRReady DPAAvailable EUData residency

The full pack is being finished. Here is exactly what is in it, and what is available today.

Omie diligence pack v1, dated and versioned
ISO 27001 and ISO 9001 certificates Available
Security and architecture overview Available
Data Processing Agreement and sub-processors Available
EU data residency statement Available
Vendor questionnaire and pen-test summary In progress
An illustration of the pack, not a screenshot
eu region
data residency
one link
forward and done

audited, not asserted

Certified where it counts.

Omie holds ISO 27001 for information security and ISO 9001 for quality management, both issued by an accredited body and both in the pack. SOC 2 Type II is in progress, and it will read that way until the report is issued.

ISO 27001 Information security management Certified
ISO 9001 Quality management Certified
SOC 2 Type II Independent controls audit In progress

Both ISO certificates can be verified with the issuing body. The day SOC 2 Type II completes, this page will say certified, and not a day sooner.

the six things reviewers ask for

Answers your team can forward.

Green means it is available today. Marigold means it is on the way. We never show a status we have not earned.

Vendor diligence questionnaire

Our answers to the questions your team already asks, filled in and ready to forward.

In progress

Security overview

How we host, encrypt, and access your data today. ISO 27001 and ISO 9001 certificates attached, SOC 2 Type II status dated plainly.

Available on request

Data Processing Agreement

A signable DPA with the sub-processor list, ready for your legal team to redline.

Available

EU data residency

Where your organization's data lives, stated plainly, with the hosting region named.

Available on Business

Invoicing with PO, NetSuite-ready

Purchase orders, USD invoices, and vendor onboarding forms without the back and forth.

Available

SSO and SCIM provisioning

Single sign-on through your identity provider is available on Business today. Automatic seat provisioning and deprovisioning through SCIM is in progress, so this line will change when it ships.

SSO available, SCIM in progress

what lands in your reviewer's inbox

One link. The whole pack.

Forward a single page and every document sits behind it, versioned and dated. Here is each item and where it stands right now.

In the packStatusWhat it covers
ISO 27001 and ISO 9001 certificates Available Current certificates for information security and quality management, issued by an accredited body and verifiable with it.
Security overview Available How we host, encrypt, and access data, shared on request with the SOC 2 Type II status dated.
DPA template Available A signable Data Processing Agreement your legal team can redline.
Sub-processor list Available Every sub-processor named, versioned, and dated, so a change is easy to spot.
Data-residency options Available EU hosting region for Business organizations, with the region named.
Pen-test summary On request A summary shared under NDA once the current test round completes.
SSO and SCIM guide Partly ready SSO setup for your identity provider today. The SCIM guide follows when provisioning ships.

No badge we have not earned. When a status above changes, this page changes with it.

three moves, no maze

How buying works.

Short by design. You can pilot before you commit, and scale seats only as people actually use them.

1

Get the diligence pack

One link with the security overview, DPA, sub-processors, and residency, ready to send straight to your reviewer.

2

Run a pilot

Start a small paid pilot, or the free tier, so your people feel the daily habit and you see real skill lift before a full rollout.

3

Roll out with SSO, SCIM and a PO

Provision seats through your identity provider, pay by purchase order or card, and add seats as adoption grows.

why procurement teams like it

Fewer emails, cleaner file.

A vendor that answers before you ask makes the whole review shorter. Omie is built to hand your team a tidy, honest file on day one.

One link, not a scavenger hunt

Every document your reviewer needs sits behind a single page, so nothing gets lost across five email threads.

Priced in plain sight

Business is $15 a seat a month, listed on the pricing page. No hidden minimums and no forced call before you can see a number.

Honest about status

ISO 27001 and ISO 9001 are certified, and the certificates are in the pack. SOC 2 Type II is in progress and we say so, never dressed up as done.

Pay per seat, cancel clean

Seats map to active people, deprovisioning frees them, and cancelling takes two clicks with a 14-day refund window.

7
documents in the pack
Versioned and dated
2
ISO certifications held
27001 and 9001, in the pack
2
clicks to cancel
14-day refund window

The fastest security review is the one where the vendor already answered the question.

the full posture, in one place

The security posture lives here.

Encryption, tenant isolation, access controls, hosting, the ISO certificates, and where the SOC 2 Type II audit stands, written for a reviewer rather than a marketer. The pack points back to this same page, so nothing goes stale in two places.

what the posture covers

  • ISO 27001 and ISO 9001 certified
  • Encryption in transit and at rest
  • Row-level tenant isolation, one org can never read another
  • Least-privilege access with an audit trail
  • EU hosting region available on Business
  • SOC 2 Type II in progress, status dated on the page

asked and answered

Procurement questions, answered.

The questions a vendor call would stall on, written out here instead.

Where does our data live?

Business organizations can be hosted in an EU region, and the pack names the exact region. The residency statement is part of the diligence pack and is available today.

Who are your sub-processors?

Every sub-processor is named in a versioned, dated list that ships with the DPA. The current list is on the security page. When the list changes, the version changes too, so a review is easy to repeat.

Do you sign a DPA?

Yes. There is a signable Data Processing Agreement ready for your legal team to redline, with the sub-processor list attached. Ask for it and it comes back the same day.

Are you ISO certified?

Yes. Omie holds ISO 27001 for information security management and ISO 9001 for quality management, both issued by an accredited certification body. The certificates are part of the diligence pack, so your reviewer can check them directly.

What is your SOC 2 status?

SOC 2 Type II is in progress. We will not describe it as certified until the report is issued, and the security overview states exactly where it stands, with a date.

Can we pay by invoice and PO?

Yes. Business supports purchase orders and USD invoices, and our billing details fit a NetSuite vendor onboarding without a lot of back and forth.

Do you support SSO and SCIM?

Single sign-on through your identity provider is available on Business today. SCIM provisioning is in progress, and the setup guide follows the moment it ships.

one email, when it ships

Get notified when it's ready.

Leave your work email and the full pack lands in your inbox the day it is complete. Nothing else, no newsletter, no drip sequence.

Reviewing now? Read the security posture See Business pricing

ISO 27001Certified ISO 9001Certified SOC 2 Type IIIn progress GDPRReady DPAAvailable

EU data residency available. Priced at $15 a seat a month.

scan learn experience author perform manage happy insights

Ten modules, one engine, one security boundary. Your review covers all of it at once.