Security

Built like we'd use it ourselves.

Because we do. Every person on the team runs their own Omie account against the same infrastructure you'd be on. The guarantees below aren't for a sales deck — they're the bar we hold ourselves to.

01

End-to-end encryption

TLS 1.3 in transit, AES-256 at rest. Database-level field encryption for reflections — not even we can read them in plaintext.

02

Zero third-party sharing

No ad networks. No data brokers. No retargeting pixels. The list of companies we share your data with has one name: Stripe, for payments.

03

GDPR compliant

EU-only infrastructure, DPA available on request. Full Article 15/17 rights exposed in the app — export or delete without talking to a human.

04

SOC 2 Type II infrastructure

Hosted on Supabase (SOC 2 Type II certified, ISO 27001). Vulnerability scanning nightly, pen tests quarterly, audit logs for 365 days.

SOC 2
Type II
GDPR
EU DPA ready
ISO 27001
via Supabase
DPIA
available
Need the full security pack?
DPA, SOC 2 report, pen-test summary, subprocessor list.
© 2026 Omie B.V. · Amsterdamomar@meetomie.com